7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-54327
LAN Controller Web
9.3
CRITICAL
EPSS
2.0%
2023 CWE-862 2 PoCs

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

CVE-2023-53983
Anevia Flamingo XL/XS General
9.3
CRITICAL
EPSS
0.7%
2023 CWE-798 1 PoC

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

CVE-2023-54335
eXtplorer Web
9.3
CRITICAL
EPSS
0.6%
2023 CWE-306 1 PoC

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

CVE-2023-54339
Webgrind Web
9.3
CRITICAL
EPSS
0.7%
2023 CWE-78 1 PoC

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.

CVE-2023-36534
Zoom Desktop Client for Windows Windows
9.3
CRITICAL
EPSS
0.6%
2023 CWE-22 1 PoC

Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-53969
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.

CVE-2023-44393
Piwigo Web ⚡ nuclei
9.3
CRITICAL
EPSS
6.2%
2023 CWE-79 0 PoCs

Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject malicious HTML and JS code into the HTML page, which could then be executed by admin users when they visit the URL with the payload. The vulnerability is caused by the insecure injection of the `plugin_id` value from the URL into the HTML page. An attacker can exploit this vulnerability by crafting a malicious URL that

CVE-2023-7330
NBR Series Routers Web Networking
9.3
CRITICAL
EPSS
0.8%
2023 CWE-434 1 PoC

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.

CVE-2023-53967
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.

CVE-2023-7311
Flow Control Router Networking
9.3
CRITICAL
EPSS
0.3%
2023 CWE-78 2 PoCs

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

CVE-2023-54329
Inbit Messenger General
9.3
CRITICAL
EPSS
0.6%
2023 CWE-121 1 PoC

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVE-2023-7334
T+ General
9.3
CRITICAL
EPSS
0.3%
2023 CWE-502 1 PoC

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observe

CVE-2023-48788
🔥 KEV FortiClientEMS Networking Database
9.3
CRITICAL
EPSS
94.1%
2023 CWE-89 5 PoCs

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2023-7304
RG-UAC Web
9.3
CRITICAL
EPSS
2.5%
2023 CWE-78 1 PoC

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful exploitation can yield full control of the application process and may lead to system-level access depending on the service privileges. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

CVE-2023-42789
FortiOS Web Networking
9.3
CRITICAL
EPSS
30.0%
2023 CWE-787 2 PoCs

A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

CVE-2023-53895
PimpMyLog Web
9.3
CRITICAL
EPSS
0.7%
2023 CWE-285 1 PoC

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.

CVE-2023-53966
SOUND4 LinkAndShare Transmitter General
9.3
CRITICAL
EPSS
0.2%
2023 CWE-134 2 PoCs

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbitrary code and crash the application.

CVE-2023-28787
Quiz And Survey Master Database ⚡ nuclei
9.3
CRITICAL
EPSS
32.1%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

CVE-2023-53923
Ulicms Web
9.3
CRITICAL
EPSS
0.2%
2023 CWE-862 1 PoC

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVE-2023-53955
Impact/Pulse/First General
9.3
CRITICAL
EPSS
0.7%
2023 CWE-639 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.