7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-51952
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

CVE-2023-20864
VMware Aria Operations for Logs (formerly vRealize Log Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVE-2023-30967
com.palantir.meta:orbital-simulator General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVE-2023-32645
YF325 Web
9.8
CRITICAL
EPSS
0.1%
2023 CWE-489 2 PoCs

A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

CVE-2023-32653
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-191 1 PoC

An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2023-6019
ray-project/ray Web
9.8
CRITICAL
EPSS
88.8%
2023 CWE-78 7 PoCs

A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

CVE-2023-34051
VMware Aria Operations for Logs General
9.8
CRITICAL
EPSS
57.7%
2023 1 PoC

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2023-20520
1st Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

CVE-2023-27654
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.

CVE-2023-38823
Software Genérico Web
9.8
CRITICAL
EPSS
4.1%
2023 2 PoCs

Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.

CVE-2023-23461
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Libpeconv – access violation, before commit b076013 (30/11/2022).

CVE-2023-34399
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library contains vulnerability integer overflow.

CVE-2023-33443
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

CVE-2023-6049
Estatik Real Estate Plugin Web Windows
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

CVE-2023-35160
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
12.1%
2023 CWE-87 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to perform a XSS, e.g. by using URL such as: > xwiki/bin/view/XWiki/Main xpage=resubmit&resubmit=javascript:alert(document.domain)&xback=javascript:alert(document.domain). This vulnerability exists since XWiki 2.5-milestone-2. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-34992
FortiSIEM Web Networking
9.7
CRITICAL
EPSS
75.9%
2023 CWE-78 2 PoCs

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

CVE-2023-35159
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
5.1%
2023 CWE-87 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template to perform a XSS, e.g. by using URL such as: > xwiki/bin/deletespace/Sandbox/?xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 3.4-milestone-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-35162
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
15.6%
2023 CWE-79 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions template to perform a XSS, e.g. by using URL such as: > <hostname>/xwiki/bin/get/FlamingoThemes/Cerulean xpage=xpart&vm=previewactions.vm&xcontinue=javascript:alert(document.domain). This vulnerability exists since XWiki 6.1-rc-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-35161
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
15.6%
2023 CWE-87 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to perform a XSS, e.g. by using URL such as: > xwiki/bin/view/AppWithinMinutes/DeleteApplication?appName=Menu&resolve=true&xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.2-milestone-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-35158
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
11.2%
2023 CWE-87 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to perform a XSS, e.g. by using URL such as: > /xwiki/bin/view/XWiki/Main?xpage=restore&showBatch=true&xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 9.4-rc-1. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.