7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34644
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
11.0%
2023 1 PoC

Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points AP_3.0(1)B11P218, NBC series wireless controllers AC_3.0(1)B11P86 allows unauthorized remote attackers to gain the highest privileges via crafted POST request to /cgi-bin/luci/api/auth.

CVE-2023-21255
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-48808
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-39005
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

CVE-2023-25433
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV.

CVE-2023-47437
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script.

CVE-2023-48028
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

CVE-2023-44765
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.

CVE-2023-47326
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

CVE-2023-47470
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c

CVE-2023-33562
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-52603
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 to 32768 UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dtree.c:1971:9 index -2 is out of range for type 'struct dtslot [128]' CPU: 0 PID: 3613 Comm: syz-executor270 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1b1/0x28e lib/

CVE-2023-20597
Ryzen™ 3000 Series Desktop Processors “Matisse” General
N/A
UNKNOWN
EPSS
0.1%
2023 CWE-824 1 PoC

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

CVE-2023-37165
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2023 1 PoC

Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.

CVE-2023-44807
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

CVE-2023-34960
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 12 PoCs

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVE-2023-33831
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 4 PoCs

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2023-5575
Server General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.

CVE-2023-0656
SonicOS Networking
N/A
UNKNOWN
EPSS
31.5%
2023 CWE-121 1 PoC

A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.