7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-35722
RAX30 Networking
8.8
HIGH
EPSS
0.8%
2023 CWE-78 1 PoC

NETGEAR RAX30 UPnP Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of UPnP port mapping requests. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20429.

CVE-2023-4897
mintplex-labs/anything-llm General
8.7
HIGH
EPSS
0.1%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-53908
HiSecOS General
8.7
HIGH
EPSS
0.0%
2023 CWE-269 1 PoC

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVE-2023-27501
NetWeaver AS for ABAP and ABAP Platform General
8.7
HIGH
EPSS
0.6%
2023 CWE-22 1 PoC

SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this attack, no data can be read but potentially critical OS files can be deleted making the system unavailable, causing significant impact on both availability and integrity

CVE-2023-53933
Serendipity Web
8.7
HIGH
EPSS
0.8%
2023 CWE-434 1 PoC

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.

CVE-2023-0050
GitLab DevOps Web
8.7
HIGH
EPSS
59.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVE-2023-31223
Software Genérico Web
8.7
HIGH
EPSS
0.4%
2023 2 PoCs

Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

CVE-2023-53921
SitemagicCMS Web
8.7
HIGH
EPSS
0.6%
2023 CWE-434 1 PoC

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

CVE-2023-6017
h2oai/h2o-3 Cloud
8.7
HIGH
EPSS
0.2%
2023 CWE-840 1 PoC

H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

CVE-2023-7308
SecGate3600 Firewall Networking
8.7
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The affected component fails to enforce authentication checks on POST requests to retrieve user data. An unauthenticated remote attacker can exploit this flaw to obtain sensitive information, including user identifiers and configuration details, by sending crafted requests to the vulnerable endpoint. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-06-18

CVE-2023-26222
TIBCO EBX Web
8.7
HIGH
EPSS
0.4%
2023 1 PoC

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.

CVE-2023-53773
MiniDVBLinux General
8.7
HIGH
EPSS
0.4%
2023 CWE-306 2 PoCs

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.

CVE-2023-53952
Dotclear Web
8.7
HIGH
EPSS
0.9%
2023 CWE-434 1 PoC

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the uploaded file is accessed, enabling arbitrary code execution on the server.

CVE-2023-53924
Ulicms Web
8.7
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.

CVE-2023-5422
OTRS General
8.7
HIGH
EPSS
0.2%
2023 CWE-295 1 PoC

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before

CVE-2023-53873
SyncBreeze DevOps
8.7
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability.

CVE-2023-53971
WebTareas Web
8.7
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVE-2023-53734
dawa-pharma Database
8.7
HIGH
EPSS
0.2%
2023 CWE-89 2 PoCs

dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.

CVE-2023-53970
Screen SFT DAB 600/C Web
8.7
HIGH
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.

CVE-2023-53917
Affiliate Me Web Database
8.7
HIGH
EPSS
0.0%
2023 CWE-89 1 PoC

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.