7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-41646
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/

CVE-2023-23298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.

CVE-2023-46386
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-2026
Image Protector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2530
Puppet Enterprise General
N/A
UNKNOWN
EPSS
7.8%
2023 1 PoC

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CVE-2023-37164
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.

CVE-2023-5240
Server General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2023-51020
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVE-2023-50917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2023 3 PoCs

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVE-2023-5725
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVE-2023-41613
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

CVE-2023-40852
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

CVE-2023-5886
Export any WordPress data to XML/CSV Web Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

CVE-2023-24130
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2023-43871
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-43869
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

CVE-2023-38352
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-4350
Chrome General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVE-2023-20589
Ryzen™ 3000 Series Desktop Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.