7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-49313
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2023 1 PoC

A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.

CVE-2023-40137
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-36622
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

CVE-2023-29735
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.

CVE-2023-20787
MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6883, MT8167, MT8167S, MT8168, MT8321, MT8362A, MT8365 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS07648734.

CVE-2023-24675
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

CVE-2023-40834
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

CVE-2023-0274
URL Params Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The URL Params WordPress plugin before 2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-38632
Software Genérico General
N/A
UNKNOWN
EPSS
29.1%
2023 1 PoC

async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.

CVE-2023-38356
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-52277
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Royal RoyalTSX before 6.0.2.1 allows attackers to cause a denial of service (Heap Memory Corruption and application crash) or possibly have unspecified other impact via a long hostname in an RTSZ file, if the victim clicks on Test Connection. This occurs during SecureGatewayHost object processing in RAPortCheck.createNWConnection.

CVE-2023-38432
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

CVE-2023-36940
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.

CVE-2023-45574
Software Genérico General
N/A
UNKNOWN
EPSS
22.6%
2023 1 PoC

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.

CVE-2023-37250
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.

CVE-2023-34852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVE-2023-42326
Software Genérico Web
N/A
UNKNOWN
EPSS
84.8%
2023 2 PoCs

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

CVE-2023-43757
WRC-2533GHBK2-T Networking
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.

CVE-2023-46468
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.

CVE-2023-51201
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.