94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-50423
sap-xssec Web
9.1
CRITICAL
EPSS
0.5%
2023 CWE-749 1 PoC

SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2023-38428
Software Genérico Windows
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.

CVE-2023-29534
Firefox for Android General
9.1
CRITICAL
EPSS
0.5%
2023 5 PoCs

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVE-2023-47873
WP Child Theme Generator General ⚡ nuclei
9.1
CRITICAL
EPSS
13.0%
2023 CWE-434 0 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

CVE-2023-2034
froxlor/froxlor General
9.1
CRITICAL
EPSS
9.0%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

CVE-2023-31114
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.

CVE-2023-29722
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.

CVE-2023-50424
github.com/sap/cloud-security-client-go Cloud
9.1
CRITICAL
EPSS
0.5%
2023 CWE-749 1 PoC

SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

CVE-2024-28335
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.

CVE-2024-57971
KNOWAGE Web
9.1
CRITICAL
EPSS
0.0%
2024 CWE-99 1 PoC

DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:comp/env/jdbc/ occurs at the beginning of a JNDI Name.

CVE-2024-45438
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2024 2 PoCs

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication.

CVE-2024-36248
Multiple MFPs (multifunction printers) Web Cloud
9.1
CRITICAL
EPSS
0.2%
2024 CWE-798 3 PoCs

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-51060
Software Genérico Web Database
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

CVE-2024-46310
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
83.0%
2024 2 PoCs

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

CVE-2024-32848
EPM Database
9.1
CRITICAL
EPSS
50.8%
2024 1 PoC

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2024-37404
Connect Secure General
9.1
CRITICAL
EPSS
86.0%
2024 1 PoC

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

CVE-2024-10004
Firefox for iOS Web
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

CVE-2024-45168
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.

CVE-2024-22393
Apache Answer Web
9.1
CRITICAL
EPSS
26.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

CVE-2024-39603
Wavlink AC3000 Web
9.1
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.