7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24653
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.

CVE-2023-24078
Software Genérico Web
8.8
HIGH
EPSS
67.1%
2023 4 PoCs

Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

CVE-2023-1534
Chrome General
8.8
HIGH
EPSS
0.4%
2023 2 PoCs

Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-36542
Apache NiFi Web
8.8
HIGH
EPSS
1.2%
2023 CWE-94 2 PoCs

Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code execution. The resolution introduces a new Required Permission for referencing remote resources, restricting configuration of these components to privileged users. The permission prevents unprivileged users from configuring Processors and Controller Services annotated with the new Reference Remote Resources restriction. Upgrading to Apache NiFi 1.23.0 is the recomme

CVE-2023-4863
🔥 KEV Chrome General
8.8
HIGH
EPSS
94.1%
2023 14 PoCs

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVE-2023-0261
WP TripAdvisor Review Slider Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
32.9%
2023 1 PoC

The WP TripAdvisor Review Slider WordPress plugin before 10.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-31061
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Repetier Server through 1.4.10 does not have CSRF protection.

CVE-2023-2574
EKI-1524 General
8.8
HIGH
EPSS
1.4%
2023 CWE-78 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-33284
Software Genérico General
8.8
HIGH
EPSS
1.2%
2023 1 PoC

Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.

CVE-2023-22493
RSSHub Web Networking
8.8
HIGH
EPSS
0.1%
2023 CWE-918 1 PoC

RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to send arbitrary HTTP requests from the server to other servers or resources on the network. An attacker can exploit this vulnerability by sending a request to the affected routes with a malicious URL. An attacker could also use this vulnerability to send requests to internal or any other servers or resources on the network, potentially gain access to sensitive information that would not normally be accessible and amplifying the impact of the a

CVE-2023-6700
Cookie Information | Free GDPR Consent Solution Web Windows
8.8
HIGH
EPSS
29.2%
2023 CWE-862 1 PoC

The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit arbitrary site options which can be used to create administrator accounts.

CVE-2023-49367
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user.

CVE-2023-50071
Software Genérico Web Database
8.8
HIGH
EPSS
11.1%
2023 2 PoCs

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department via id or name.

CVE-2023-32560
Avalanche General
8.8
HIGH
EPSS
92.2%
2023 4 PoCs

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

CVE-2023-46526
Software Genérico Cloud
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

CVE-2023-50233
Ignition General
8.8
HIGH
EPSS
3.7%
2023 CWE-22 1 PoC

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getJavaExecutable method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context

CVE-2023-23529
🔥 KEV iOS and iPadOS General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-23295
Software Genérico General
8.8
HIGH
EPSS
2.3%
2023 1 PoC

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVE-2023-54340
WorkOrder CMS Web Database
8.8
HIGH
EPSS
0.2%
2023 CWE-89 1 PoC

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execute administrative commands.

CVE-2023-50702
Software Genérico Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.