94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0255
Enable Media Replace Web Windows
8.8
HIGH
EPSS
1.4%
2023 2 PoCs

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CVE-2023-46521
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

CVE-2023-1997
SIMULIA 3DOrchestrate Web
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

CVE-2023-1406
JetEngine Web Windows
8.8
HIGH
EPSS
7.9%
2023 1 PoC

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.

CVE-2023-37213
SYnergy Fingerprint Terminals General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'

CVE-2023-48841
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

CVE-2023-6022
prefecthq/prefect Web
8.8
HIGH
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.

CVE-2023-1647
calcom/cal.com General
8.8
HIGH
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.

CVE-2023-6845
CommentTweets Web Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2023-41257
Foxit Reader Web
8.8
HIGH
EPSS
0.0%
2023 CWE-843 2 PoCs

A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-1381
WP Meta SEO Web Windows
8.8
HIGH
EPSS
9.5%
2023 2 PoCs

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

CVE-2023-24330
Software Genérico General
8.8
HIGH
EPSS
1.0%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

CVE-2023-24051
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

CVE-2023-4536
My Account Page Editor Web Windows
8.8
HIGH
EPSS
0.6%
2023 1 PoC

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVE-2023-33781
Software Genérico General
8.8
HIGH
EPSS
42.4%
2023 2 PoCs

An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.

CVE-2023-49982
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

CVE-2023-0698
Chrome General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVE-2023-27568
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=

CVE-2023-24519
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the ping tool utility.

CVE-2023-0388
Random Text Web Database Windows
8.8
HIGH
EPSS
1.0%
2023 1 PoC

The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.