4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.4%
2023 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CVE-2023-0037
10Web Map Builder for Google Maps Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
65.6%
2023 1 PoC

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2023-29919
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
91.9%
2023 2 PoCs

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

CVE-2023-32653
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-191 1 PoC

An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2023-28765
BusinessObjects Business Intelligence Platform (Promotion Management) General
9.8
CRITICAL
EPSS
0.8%
2023 CWE-200 1 PoC

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.

CVE-2023-26918
Software Genérico General
9.8
CRITICAL
EPSS
7.2%
2023 1 PoC

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

CVE-2023-41998
Arcserve UDP General
9.8
CRITICAL
EPSS
15.3%
2023 CWE-434 1 PoC

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.

CVE-2023-50651
Software Genérico General
9.8
CRITICAL
EPSS
2.9%
2023 1 PoC

TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.

CVE-2023-46012
Software Genérico Web
9.8
CRITICAL
EPSS
34.6%
2023 2 PoCs

Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

CVE-2023-23607
Dasherr Web
9.8
CRITICAL
EPSS
4.4%
2023 CWE-434 2 PoCs

erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads a php file they can execute code on the server. This issue has been addressed in version 1.05.00. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2023-28753
netconsd General
9.8
CRITICAL
EPSS
8.1%
2023 1 PoC

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.

CVE-2023-23331
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.

CVE-2023-23064
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.

CVE-2023-25279
Software Genérico General
9.8
CRITICAL
EPSS
46.9%
2023 1 PoC

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

CVE-2023-25367
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

CVE-2023-5877
affiliate-toolkit Web Windows
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

CVE-2023-28507
UniData General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-400 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.

CVE-2023-23306
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.

CVE-2023-31116
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

CVE-2023-24480
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-116 1 PoC

Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading and versioning.