728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29747
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.

CVE-2023-30547
vm2 General
9.8
CRITICAL
EPSS
84.9%
2023 CWE-74 4 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

CVE-2023-29741
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.

CVE-2023-27203
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

CVE-2023-29862
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.

CVE-2023-31446
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
91.7%
2023 1 PoC

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

CVE-2023-36812
opentsdb General
9.8
CRITICAL
EPSS
84.3%
2023 CWE-74 1 PoC

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.

CVE-2023-23305
Software Genérico Web
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.

CVE-2023-45249
🔥 KEV Acronis Cyber Infrastructure General
9.8
CRITICAL
EPSS
93.5%
2023 CWE-1393 1 PoC

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

CVE-2023-49237
Software Genérico General
9.8
CRITICAL
EPSS
69.8%
2023 1 PoC

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

CVE-2023-30189
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().

CVE-2023-34124
GMS Networking ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2023 CWE-305 1 PoC

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVE-2023-26689
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVE-2023-34750
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

CVE-2023-51969
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.

CVE-2023-49340
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

CVE-2023-35968
YF325 General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-190 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-27584
Dragonfly2 Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
66.2%
2023 CWE-321 0 PoCs

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-31541
Software Genérico General
9.8
CRITICAL
EPSS
5.5%
2023 1 PoC

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

CVE-2023-34756
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.