7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29803
Software Genérico Networking
9.8
CRITICAL
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.

CVE-2023-29961
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

CVE-2023-26785
Software Genérico Database
9.8
CRITICAL
EPSS
63.0%
2023 1 PoC

MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVE-2023-30805
Net-Gen Application Firewall Web Networking
9.8
CRITICAL
EPSS
14.8%
2023 CWE-78 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

CVE-2023-26822
Software Genérico General
9.8
CRITICAL
EPSS
25.7%
2023 1 PoC

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.

CVE-2023-37177
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.3%
2023 1 PoC

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.

CVE-2023-32224
DSL-224 firmware version 3.0.10 General
9.8
CRITICAL
EPSS
0.9%
2023 CWE-307 1 PoC

D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

CVE-2023-27645
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

CVE-2023-51971
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.

CVE-2023-46817
Software Genérico Web
9.8
CRITICAL
EPSS
0.8%
2023 3 PoCs

An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary PHP objects into the application scope, allowing them to perform a variety of attacks, such as executing arbitrary PHP code.

CVE-2023-29801
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.

CVE-2023-3368
Chamilo Web ⚡ nuclei
9.8
CRITICAL
EPSS
89.0%
2023 CWE-78 1 PoC

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

CVE-2023-36091
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-50061
Software Genérico Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

CVE-2023-27388
T&D Corporation and ESPEC MIC CORP. data logger products General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

CVE-2023-6231
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-787 2 PoCs

Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-33735
Software Genérico General
9.8
CRITICAL
EPSS
53.2%
2023 1 PoC

D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.

CVE-2023-42282
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2023 2 PoCs

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CVE-2023-24349
Software Genérico Networking
9.8
CRITICAL
EPSS
1.1%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

CVE-2023-34566
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.