7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6845
CommentTweets Web Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2023-41257
Foxit Reader Web
8.8
HIGH
EPSS
0.0%
2023 CWE-843 2 PoCs

A type confusion vulnerability exists in the way Foxit Reader 12.1.2.15356 handles field value properties. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-1381
WP Meta SEO Web Windows
8.8
HIGH
EPSS
9.5%
2023 2 PoCs

The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.

CVE-2023-24330
Software Genérico General
8.8
HIGH
EPSS
1.0%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

CVE-2023-24051
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

CVE-2023-4536
My Account Page Editor Web Windows
8.8
HIGH
EPSS
0.6%
2023 1 PoC

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVE-2023-33781
Software Genérico General
8.8
HIGH
EPSS
42.4%
2023 2 PoCs

An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.

CVE-2023-49982
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

CVE-2023-0698
Chrome General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVE-2023-27568
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=

CVE-2023-24519
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the ping tool utility.

CVE-2023-0388
Random Text Web Database Windows
8.8
HIGH
EPSS
1.0%
2023 1 PoC

The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.

CVE-2023-49085
cacti Web Database
8.8
HIGH
EPSS
91.4%
2023 CWE-89 1 PoC

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.

CVE-2023-52291
Apache StreamPark (incubating) Web
8.8
HIGH
EPSS
0.4%
2023 CWE-77 1 PoC

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vu

CVE-2023-5766
Remote Desktop Manager Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

CVE-2023-36092
Software Genérico Web
8.8
HIGH
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0765
Gallery by BestWebSoft Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

CVE-2023-27935
macOS General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A remote user may be able to cause unexpected app termination or arbitrary code execution.

CVE-2023-21674
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
11.6%
2023 CWE-416 1 PoC

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2023-24871
Windows Server 2022 Windows
8.8
HIGH
EPSS
59.6%
2023 CWE-190 1 PoC

Windows Bluetooth Service Remote Code Execution Vulnerability