728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-35162
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
15.6%
2023 CWE-79 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions template to perform a XSS, e.g. by using URL such as: > <hostname>/xwiki/bin/get/FlamingoThemes/Cerulean xpage=xpart&vm=previewactions.vm&xcontinue=javascript:alert(document.domain). This vulnerability exists since XWiki 6.1-rc-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-50257
Fast-DDS General
9.7
CRITICAL
EPSS
0.2%
2023 CWE-284 1 PoC

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, al

CVE-2023-33242
Wallet General
9.6
CRITICAL
EPSS
5.8%
2023 2 PoCs

Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.

CVE-2023-0488
pyload/pyload Web
9.6
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.

CVE-2023-33241
Wallet General
9.6
CRITICAL
EPSS
0.3%
2023 1 PoC

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

CVE-2023-39213
Zoom Desktop Client for Windows and Zoom VDI Client Windows
9.6
CRITICAL
EPSS
1.0%
2023 CWE-176 1 PoC

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-1720
Bitrix24 Web
9.6
CRITICAL
EPSS
1.0%
2023 CWE-434 1 PoC

Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.

CVE-2023-28347
Software Genérico Web Windows
9.6
CRITICAL
EPSS
1.7%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.

CVE-2023-5241
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php.

CVE-2023-39216
Zoom Desktop Client for Windows Windows
9.6
CRITICAL
EPSS
0.4%
2023 CWE-80 1 PoC

Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-27500
NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) General
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.

CVE-2023-48728
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
17.4%
2023 CWE-79 2 PoCs

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVE-2023-41265
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.6
CRITICAL
EPSS
92.4%
2023 1 PoC

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVE-2023-34990
FortiWLM Networking ⚡ nuclei
9.6
CRITICAL
EPSS
72.9%
2023 CWE-23 0 PoCs

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVE-2023-22524
Companion for Mac General
9.6
CRITICAL
EPSS
32.0%
2023 2 PoCs

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

CVE-2023-6753
mlflow/mlflow General
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

CVE-2023-5820
Thumbnail Slider With Lightbox Web Windows
9.6
CRITICAL
EPSS
0.1%
2023 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-3526
CLOUD CLIENT 1101T-TX/TX Web Networking Cloud
9.6
CRITICAL
EPSS
0.7%
2023 CWE-79 2 PoCs

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

CVE-2023-5212
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3.

CVE-2023-27269
NetWeaver Application Server for ABAP and ABAP Platform General
9.6
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files.  In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.