7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-44445
CAX30 Networking
8.8
HIGH
EPSS
3.2%
2023 CWE-121 1 PoC

NETGEAR CAX30 SSO Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the sso binary. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19058.

CVE-2023-37221
BOT Web
8.8
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

CVE-2023-4704
instantsoft/icms2 Web
8.8
HIGH
EPSS
0.1%
2023 CWE-15 1 PoC

External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-42491
EisBaer Scada General
8.8
HIGH
EPSS
0.2%
2023 CWE-285 1 PoC

EisBaer Scada - CWE-285: Improper Authorization

CVE-2023-41993
🔥 KEV macOS General
8.8
HIGH
EPSS
24.2%
2023 4 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-26217
TIBCO EBX Add-ons Database Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-89 1 PoC

The Data Exchange Add-on component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged user with import permissions and network access to the EBX server to execute arbitrary SQL statements on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.17 and below, versions 5.6.2 and below, version 6.1.0.

CVE-2023-50219
Ignition General
8.8
HIGH
EPSS
8.9%
2023 CWE-502 1 PoC

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the RunQuery class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21625.

CVE-2023-5178
Red Hat Enterprise Linux 8 General
8.8
HIGH
EPSS
8.6%
2023 CWE-416 1 PoC

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.

CVE-2023-33533
Software Genérico General
8.8
HIGH
EPSS
6.5%
2023 1 PoC

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

CVE-2023-6532
WP Blogs' Planetarium Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-2833
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema Web Windows
8.8
HIGH
EPSS
26.8%
2023 CWE-269 1 PoC

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_screen_options[option]' and 'wp_screen_options[value]' parameters during a screen option update.

CVE-2023-4759
Eclipse JGit General
8.8
HIGH
EPSS
1.0%
2023 CWE-59 3 PoCs

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploi

CVE-2023-26314
Software Genérico General
8.8
HIGH
EPSS
1.2%
2023 2 PoCs

The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono CLR interpreter.

CVE-2023-28349
Software Genérico Windows
8.8
HIGH
EPSS
0.7%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that functions similarly to the Teacher Console. This can compel Student Consoles to connect and put themselves at risk automatically. Connected Student Consoles can be compelled to write arbitrary files to arbitrary locations on disk with NT AUTHORITY/SYSTEM level permissions, enabling remote code execution.

CVE-2023-30854
AVideo Web
8.8
HIGH
EPSS
65.7%
2023 CWE-78 1 PoC

AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.

CVE-2023-27826
Software Genérico General
8.8
HIGH
EPSS
17.3%
2023 1 PoC

SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

CVE-2023-32697
sqlite-jdbc Database
8.8
HIGH
EPSS
5.5%
2023 CWE-94 1 PoC

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

CVE-2023-24523
Host Agent Service General
8.8
HIGH
EPSS
0.1%
2023 CWE-668 1 PoC

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges.  The OS command can read or modify any user or system data and can make the system unavailable.

CVE-2023-51014
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi

CVE-2023-4827
File Manager Pro Web Windows
8.8
HIGH
EPSS
6.3%
2023 1 PoC

The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.