7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-54340
WorkOrder CMS Web Database
8.8
HIGH
EPSS
0.2%
2023 CWE-89 1 PoC

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execute administrative commands.

CVE-2023-23295
Software Genérico General
8.8
HIGH
EPSS
2.3%
2023 1 PoC

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVE-2023-3217
Chrome General
8.8
HIGH
EPSS
17.5%
2023 1 PoC

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-3421
Chrome General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-1389
🔥 KEV TP-Link Archer AX21 (AX1800) General ⚡ nuclei
8.8
HIGH
EPSS
93.5%
2023 5 PoCs

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CVE-2023-42491
EisBaer Scada General
8.8
HIGH
EPSS
0.2%
2023 CWE-285 1 PoC

EisBaer Scada - CWE-285: Improper Authorization

CVE-2023-1304
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.5%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-23529
🔥 KEV iOS and iPadOS General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-24507
NX General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.

CVE-2023-35080
Secure Access Client Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure.

CVE-2023-41504
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

CVE-2023-0953
Devolutions Server Database
8.8
HIGH
EPSS
0.7%
2023 1 PoC

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.

CVE-2023-24330
Software Genérico General
8.8
HIGH
EPSS
1.0%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

CVE-2023-32031
Microsoft Exchange Server 2019 Cumulative Update 12 Windows
8.8
HIGH
EPSS
42.1%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-49546
Software Genérico Web Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

CVE-2023-37213
SYnergy Fingerprint Terminals General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'

CVE-2023-4697
usememos/memos General
8.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-24078
Software Genérico Web
8.8
HIGH
EPSS
67.1%
2023 4 PoCs

Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

CVE-2023-23596
Software Genérico Web Networking
8.8
HIGH
EPSS
4.7%
2023 1 PoC

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.

CVE-2023-33781
Software Genérico General
8.8
HIGH
EPSS
42.4%
2023 2 PoCs

An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.