7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2240
microweber/microweber General
8.8
HIGH
EPSS
0.3%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-39370
Softswitch Web
8.8
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)

CVE-2023-24523
Host Agent Service General
8.8
HIGH
EPSS
0.1%
2023 CWE-668 1 PoC

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges.  The OS command can read or modify any user or system data and can make the system unavailable.

CVE-2023-1220
Chrome General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Heap buffer overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-38146
Windows 11 version 21H2 Windows
8.8
HIGH
EPSS
86.5%
2023 CWE-367 2 PoCs

Windows Themes Remote Code Execution Vulnerability

CVE-2023-5953
Welcart e-Commerce Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server

CVE-2023-25266
Software Genérico General
8.8
HIGH
EPSS
5.7%
2023 1 PoC

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).

CVE-2023-50159
Software Genérico Windows
8.8
HIGH
EPSS
0.0%
2023 2 PoCs

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-26876
Software Genérico Web Database
8.8
HIGH
EPSS
54.1%
2023 2 PoCs

SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.

CVE-2023-36899
Microsoft .NET Framework 4.8 General
8.8
HIGH
EPSS
70.0%
2023 CWE-20 2 PoCs

ASP.NET Elevation of Privilege Vulnerability

CVE-2023-38543
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

CVE-2023-35080
Secure Access Client Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

CVE-2023-4979
librenms/librenms Web
8.8
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.

CVE-2023-27826
Software Genérico General
8.8
HIGH
EPSS
17.3%
2023 1 PoC

SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

CVE-2023-37569
Emagic Data Center Management Suite General
8.8
HIGH
EPSS
53.1%
2023 CWE-78 1 PoC

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

CVE-2023-50223
Ignition General
8.8
HIGH
EPSS
49.0%
2023 CWE-502 1 PoC

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExtendedDocumentCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI

CVE-2023-53974
DSL-124 Wireless N300 ADSL2+ Networking
8.8
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.

CVE-2023-34253
grav Web
8.8
HIGH
EPSS
2.1%
2023 CWE-184 1 PoC

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code executio

CVE-2023-46522
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.