7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33466
Software Genérico Web
N/A
UNKNOWN
EPSS
24.7%
2023 1 PoC

Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE).

CVE-2023-22984
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Vulnerability was discovered in Axis 207W network camera. There is a reflected XSS vulnerability in the web administration portal, which allows an attacker to execute arbitrary JavaScript via URL.

CVE-2023-45866
Software Genérico General
N/A
UNKNOWN
EPSS
36.0%
2023 5 PoCs

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

CVE-2023-5931
rtMedia for WordPress, BuddyPress and bbPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

CVE-2023-51749
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."

CVE-2023-37688
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.

CVE-2023-2805
SupportCandy Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-2795
CodeColorer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-46385
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

CVE-2023-41538
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2023 1 PoC

phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

CVE-2023-46974
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 3 PoCs

Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.

CVE-2023-24367
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2023 0 PoCs

Sin descripción disponible.

CVE-2023-39107
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.

CVE-2023-39612
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.

CVE-2023-35818
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the chip to gain unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code.

CVE-2023-51023
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.

CVE-2023-52614
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop. Also add at the end a warning that we exceeded PAGE_SIZE and that stats is disabled. Return -EFBIG in the case where we don't have enough space to write the full transition table. Also document in the ABI that this function can return -EFBIG error.

CVE-2023-52458
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: block: add check that partition length needs to be aligned with block size Before calling add partition or resize partition, there is no check on whether the length is aligned with the logical block size. If the logical block size of the disk is larger than 512 bytes, then the partition size maybe not the multiple of the logical block size, and when the last sector is read, bio_truncate() will adjust the bio size, resulting in an IO error if the size of the read command is smaller than the logical block size.If integrity dat