7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43183
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack their account.

CVE-2023-4007
thorsten/phpmyfaq Web
8.8
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

CVE-2023-6866
Firefox Web
8.8
HIGH
EPSS
1.1%
2023 1 PoC

TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.

CVE-2023-40194
Foxit Reader Web
8.8
HIGH
EPSS
0.0%
2023 CWE-73 2 PoCs

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-29804
Software Genérico Windows
8.8
HIGH
EPSS
19.9%
2023 1 PoC

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.

CVE-2023-2552
unilogies/bumsys Web
8.8
HIGH
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.

CVE-2023-38346
Software Genérico General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

CVE-2023-0220
Pinpoint Booking System Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

CVE-2023-0875
WP Meta SEO Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by subscriber+ users.

CVE-2023-49502
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

CVE-2023-20046
Cisco ASR 5000 Series Software Networking
8.8
HIGH
EPSS
0.6%
2023 CWE-289 1 PoC

A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. Th

CVE-2023-43317
Software Genérico General
8.8
HIGH
EPSS
7.0%
2023 1 PoC

An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

CVE-2023-50222
Ignition General
8.8
HIGH
EPSS
3.2%
2023 CWE-502 1 PoC

Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the ResponseParser method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnera

CVE-2023-28231
Windows Server 2019 Windows
8.8
HIGH
EPSS
75.5%
2023 CWE-122 2 PoCs

DHCP Server Service Remote Code Execution Vulnerability

CVE-2023-32697
sqlite-jdbc Database
8.8
HIGH
EPSS
5.5%
2023 CWE-94 1 PoC

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

CVE-2023-34448
grav Web
8.8
HIGH
EPSS
8.8%
2023 CWE-20 1 PoC

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that could be used to invoke arbitrary unsafe functions, thereby allowing for remote code execution. A patch in version 1.74.2 overrides the built-in Twig `map()` and `reduce()` filter functions in `system/src/Grav/Common/Twig/Extension/GravExtension.php` to validate the argument passed to the filter in `$arrow`.

CVE-2023-32563
Avalanche General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 0 PoCs

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2023-2497
UserPro - Community and User Profile WordPress Plugin Web Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-352 1 PoC

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection due to the use of unserialize() on the user supplied parameter via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-35155
xwiki-platform Web ⚡ nuclei
8.8
HIGH
EPSS
47.0%
2023 CWE-79 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation.