94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-49085
cacti Web Database
8.8
HIGH
EPSS
91.4%
2023 CWE-89 1 PoC

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.

CVE-2023-52291
Apache StreamPark (incubating) Web
8.8
HIGH
EPSS
0.4%
2023 CWE-77 1 PoC

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vu

CVE-2023-5766
Remote Desktop Manager Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

CVE-2023-36092
Software Genérico Web
8.8
HIGH
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0765
Gallery by BestWebSoft Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

CVE-2023-27935
macOS General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected app termination or arbitrary code execution.

CVE-2023-21674
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
11.6%
2023 CWE-416 1 PoC

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2023-24871
Windows Server 2022 Windows
8.8
HIGH
EPSS
59.6%
2023 CWE-190 1 PoC

Windows Bluetooth Service Remote Code Execution Vulnerability

CVE-2023-6373
ArtPlacer Widget Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged editor (or above)

CVE-2023-39542
Foxit Reader Web
8.8
HIGH
EPSS
0.2%
2023 CWE-73 2 PoCs

A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-4296
Codebeamer General
8.8
HIGH
EPSS
1.0%
2023 CWE-79 2 PoCs

​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.

CVE-2023-24345
Software Genérico Networking
8.8
HIGH
EPSS
0.8%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus.

CVE-2023-50780
Apache ActiveMQ Artemis Web
8.8
HIGH
EPSS
2.7%
2023 CWE-285 1 PoC

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE. Users are recommended to upgrade to version 2.29.0 or later, which fixes the issue.

CVE-2023-21848
Communications Convergence Web Database
8.8
HIGH
EPSS
1.3%
2023 1 PoC

Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration). The supported version that is affected is 3.0.3.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-33239
TN-5900 Series General
8.8
HIGH
EPSS
1.0%
2023 CWE-78 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

CVE-2023-24052
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.

CVE-2023-33876
Foxit Reader Web
8.8
HIGH
EPSS
0.2%
2023 CWE-416 2 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-43835
Software Genérico Web
8.8
HIGH
EPSS
3.5%
2023 1 PoC

Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.

CVE-2023-4762
🔥 KEV Chrome General
8.8
HIGH
EPSS
55.8%
2023 3 PoCs

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2023-28434
🔥 KEV minio Web Cloud
8.8
HIGH
EPSS
52.1%
2023 CWE-269 1 PoC

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`.