94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29728
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.

CVE-2023-37895
Apache Jackrabbit Webapp (jackrabbit-webapp) Web
9.8
CRITICAL
EPSS
9.9%
2023 CWE-502 1 PoC

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that can be used for remote code execution over RMI. Users are advised to immediately update to versions 2.20.11 or 2.21.18. Note that earlier stable branches (1.0.x .. 2.18.x) have been EOLd already and do not receive updates anymore. In general, RMI support can expose vulnerabilities by the mere presence of an exploitabl

CVE-2023-31814
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

CVE-2023-3277
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
47.2%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

CVE-2023-50488
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 2 PoCs

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

CVE-2023-5174
Firefox Windows
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVE-2023-30945
com.palantir.gotham:clips2 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-287 1 PoC

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

CVE-2023-24331
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

CVE-2023-2449
UserPro - Community and User Profile WordPress Plugin Web Database Windows
9.8
CRITICAL
EPSS
0.6%
2023 CWE-620 2 PoCs

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-2448 and CVE-2023-2446, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit thi

CVE-2023-4188
instantsoft/icms2 Web Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-25076
SNIProxy Web
9.8
CRITICAL
EPSS
35.5%
2023 CWE-120 2 PoCs

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.

CVE-2023-31060
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.

CVE-2023-27040
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.

CVE-2023-2645
USR-G806 General
9.8
CRITICAL
EPSS
6.2%
2023 CWE-259 1 PoC

A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41. Affected is an unknown function of the component Web Management Page. The manipulation of the argument username/password with the input root leads to use of hard-coded password. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. VDB-228774 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-51952
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

CVE-2023-29531
Firefox Web
9.8
CRITICAL
EPSS
0.6%
2023 1 PoC

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVE-2023-24775
Software Genérico Web Database
9.8
CRITICAL
EPSS
31.4%
2023 1 PoC

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.

CVE-2023-33669
Software Genérico General
9.8
CRITICAL
EPSS
30.9%
2023 1 PoC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.

CVE-2023-23489
Easy Digital Downloads WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
85.2%
2023 1 PoC

The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.

CVE-2023-30328
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.