728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-45146
xxl-rpc General
9.1
CRITICAL
EPSS
3.6%
2023 CWE-502 1 PoC

XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.

CVE-2023-36645
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

CVE-2023-2259
alfio-event/alf.io General
9.1
CRITICAL
EPSS
0.5%
2023 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVE-2023-5754
PolyEco1000 General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

CVE-2023-46501
Software Genérico General
9.1
CRITICAL
EPSS
10.9%
2023 1 PoC

An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.

CVE-2023-37908
xwiki-rendering Web
9.1
CRITICAL
EPSS
1.5%
2023 CWE-83 1 PoC

XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid attribute names. This can be exploited, e.g., via the link syntax in any content that supports XWiki syntax like comments in XWiki. When a user moves the mouse over a malicious link, the malicious JavaScript code is executed in the context of the user session. When this user is a privileged user who has programming

CVE-2023-28762
SAP BusinessObjects Intelligence Platform General
9.1
CRITICAL
EPSS
0.2%
2023 CWE-200 1 PoC

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.

CVE-2023-50423
sap-xssec Web
9.1
CRITICAL
EPSS
0.5%
2023 CWE-749 1 PoC

SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-39172
Storage Box V1 General
9.1
CRITICAL
EPSS
0.4%
2023 CWE-319 2 PoCs

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

CVE-2023-5841
OpenEXR General
9.1
CRITICAL
EPSS
0.8%
2023 CWE-122 1 PoC

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVE-2023-38428
Software Genérico Windows
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.

CVE-2023-31126
xwiki-commons Web
9.1
CRITICAL
EPSS
2.7%
2023 CWE-86 1 PoC

`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes. This vulnerability does not affect restricted cleaning in HTMLCleaner as there attributes are cleaned and thus characters like `/` and `>` are removed in all attribute names. This problem has been patched in XWiki 14.10.4 and 15.0 RC1 by making sure that data attributes only contain allowed characters. There are no known workarounds apart fr

CVE-2023-47873
WP Child Theme Generator General ⚡ nuclei
9.1
CRITICAL
EPSS
13.0%
2023 CWE-434 0 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

CVE-2023-29534
Firefox for Android General
9.1
CRITICAL
EPSS
0.5%
2023 5 PoCs

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVE-2023-27290
Observability with Instana DevOps
9.1
CRITICAL
EPSS
8.5%
2023 CWE-306 1 PoC

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

CVE-2023-41807
Pandora FMS General
9.1
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissions on the system shell. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-45685
Titan MFT Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-22 1 PoC

Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

CVE-2023-2227
modoboa/modoboa General ⚡ nuclei
9.1
CRITICAL
EPSS
90.5%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-1722
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.