4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34124
GMS Networking ⚡ nuclei
9.8
CRITICAL
EPSS
91.3%
2023 CWE-305 1 PoC

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVE-2023-26689
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVE-2023-34750
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

CVE-2023-51969
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.

CVE-2023-49340
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

CVE-2023-35968
YF325 General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-190 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-27584
Dragonfly2 Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
66.2%
2023 CWE-321 0 PoCs

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-31541
Software Genérico General
9.8
CRITICAL
EPSS
5.5%
2023 1 PoC

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

CVE-2023-34756
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

CVE-2023-29665
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2023 1 PoC

D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.

CVE-2023-51801
Software Genérico Web Database
9.8
CRITICAL
EPSS
7.2%
2023 1 PoC

SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.

CVE-2023-28501
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-190 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.

CVE-2023-43373
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.2%
2023 0 PoCs

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

CVE-2023-29727
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of privilege attack.

CVE-2023-52032
Software Genérico General
9.8
CRITICAL
EPSS
16.3%
2023 1 PoC

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVE-2023-30331
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

CVE-2023-34478
Apache Shiro Web
9.8
CRITICAL
EPSS
0.0%
2023 CWE-22 1 PoC

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

CVE-2023-49693
NETGEAR ProSAFE Network Management System General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-306 2 PoCs

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

CVE-2023-52028
Software Genérico General
9.8
CRITICAL
EPSS
20.6%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

CVE-2023-38408
Software Genérico Networking
9.8
CRITICAL
EPSS
64.4%
2023 13 PoCs

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.