7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1287
ENOVIA Live Collaboration General
9.0
CRITICAL
EPSS
2.6%
2023 CWE-74 1 PoC

An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

CVE-2023-0106
usememos/memos Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-31703
Software Genérico Web
9.0
CRITICAL
EPSS
1.6%
2023 3 PoCs

Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.

CVE-2023-27882
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-27830
Software Genérico General
9.0
CRITICAL
EPSS
0.5%
2023 1 PoC

TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.

CVE-2023-28391
Gecko Platform Web
9.0
CRITICAL
EPSS
0.4%
2023 CWE-119 1 PoC

A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-21456
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVE-2023-25181
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-31422
Kibana General
9.0
CRITICAL
EPSS
0.4%
2023 CWE-532 1 PoC

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in t

CVE-2023-31247
Gecko Platform Web
9.0
CRITICAL
EPSS
0.4%
2023 CWE-119 1 PoC

A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-21975
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Customers Plugin, attacks may significantly impact additional products (scope change). Successful attac

CVE-2023-4202
EKI-1524 Web
9.0
CRITICAL
EPSS
0.2%
2023 CWE-79 3 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

CVE-2023-3086
nilsteampassnet/teampass Web
9.0
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-28379
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-119 1 PoC

A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-4978
librenms/librenms Web
9.0
CRITICAL
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

CVE-2023-50982
Software Genérico Web
9.0
CRITICAL
EPSS
0.5%
2023 1 PoC

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.

CVE-2023-27395
SoftEther VPN Networking
9.0
CRITICAL
EPSS
0.4%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-0432
DX-2100-L1-CN General
9.0
CRITICAL
EPSS
1.8%
2023 CWE-79 1 PoC

The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.

CVE-2023-1715
Bitrix24 Web
9.0
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

CVE-2023-21974
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calendar Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Team Calendar Plugin, attacks may significantly impact additional products (scope change).