94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-54330
Inbit Messenger Windows
9.3
CRITICAL
EPSS
0.4%
2023 CWE-121 1 PoC

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.

CVE-2023-53877
Bus Reservation System Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

CVE-2023-53982
PMB Web Database
9.3
CRITICAL
EPSS
0.0%
2023 CWE-89 1 PoC

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.

CVE-2023-53941
EasyPHP Webserver Web
9.3
CRITICAL
EPSS
70.5%
2023 CWE-78 1 PoC

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

CVE-2023-6569
h2oai/h2o-3 General
9.3
CRITICAL
EPSS
0.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in h2oai/h2o-3

CVE-2023-53894
phpfm Web
9.3
CRITICAL
EPSS
0.5%
2023 CWE-1390 1 PoC

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

CVE-2023-31191
ds230 General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-223 1 PoC

DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real Remote ID (RID) information and, instead, generate and transmit JSON encoded MQTT messages containing crafted RID information. Consequently, the MQTT broker, typically operated by a system integrator, will have no access to the drones’ real RID information.

CVE-2023-6013
h2oai/h2o-3 Web
9.3
CRITICAL
EPSS
0.2%
2023 CWE-79 1 PoC

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

CVE-2023-25610
FortiSwitchManager Networking
9.3
CRITICAL
EPSS
16.0%
2023 CWE-124 1 PoC

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

CVE-2023-53972
WebTareas Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

WebTareas 2.4 contains a SQL injection vulnerability in the webTareasSID cookie parameter that allows unauthenticated attackers to manipulate database queries. Attackers can exploit error-based and time-based blind SQL injection techniques to extract database information and potentially access sensitive system data.

CVE-2023-53771
MiniDVBLinux Change Root Password PoC General
9.3
CRITICAL
EPSS
1.1%
2023 CWE-306 2 PoCs

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials.

CVE-2023-53951
ever gauzy General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-347 1 PoC

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

CVE-2023-53922
TinyWebGallery Web
9.3
CRITICAL
EPSS
2.3%
2023 CWE-434 1 PoC

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.

CVE-2023-53914
Ulicms Web
9.3
CRITICAL
EPSS
1.8%
2023 CWE-639 1 PoC

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.

CVE-2023-54327
LAN Controller Web
9.3
CRITICAL
EPSS
2.0%
2023 CWE-862 2 PoCs

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

CVE-2023-53983
Anevia Flamingo XL/XS General
9.3
CRITICAL
EPSS
0.7%
2023 CWE-798 1 PoC

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

CVE-2023-54335
eXtplorer Web
9.3
CRITICAL
EPSS
0.6%
2023 CWE-306 1 PoC

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

CVE-2023-54339
Webgrind Web
9.3
CRITICAL
EPSS
0.7%
2023 CWE-78 1 PoC

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.

CVE-2023-36534
Zoom Desktop Client for Windows Windows
9.3
CRITICAL
EPSS
0.6%
2023 CWE-22 1 PoC

Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-53969
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.