7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33387
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.

CVE-2023-27635
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)

CVE-2023-43341
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter.

CVE-2023-38924
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.

CVE-2023-24131
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1_5g parameter at /goform/WifiBasicSet.

CVE-2023-20785
MT6779, MT6781, MT6785, MT6853, MT6853T, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT8168, MT8781, MT8791, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628524; Issue ID: ALPS07628524.

CVE-2023-52927
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 3 PoCs

In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some scenario, we expect the exp not to be removed when the created ct will not be confirmed, like in OVS and TC conntrack in the following patches. This patch allows exp not to be removed by setting IPS_CONFIRMED in the status of the tmpl.

CVE-2023-22906
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.

CVE-2023-51024
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface of the cstecgi .cgi.

CVE-2023-30774
libtiff General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-119 1 PoC

A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.

CVE-2023-38328
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password.

CVE-2023-39002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.6%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-43622
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
63.2%
2023 CWE-400 1 PoC

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57. Users are recommended to upgrade to version 2.4.58, which fixes the issue.

CVE-2023-20798
MT2713, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT8188, MT8195, MT8395, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In pda, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07147572; Issue ID: ALPS07421076.

CVE-2023-0159
Extensive VC Addons for WPBakery page builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2023 1 PoC

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

CVE-2023-34965
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

CVE-2023-40751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2023 2 PoCs

PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

CVE-2023-45875
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

CVE-2023-35829
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.

CVE-2023-48824
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action.