Loading HuntDB...

High-Impact Vulnerabilities

Critical + High Exploit High EPSS

Vulnerabilities that meet all three criteria: Critical/High severity, known exploits, and high probability of exploitation (EPSS ≥ 10%).

CVE-2023-26360 6 months, 2 weeks ago

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

HIGH (8.6) EPSS: 94.3% 1 exploit
Adobe ColdFusion - Local File…
CVE-2023-26347 6 months, 2 weeks ago

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

HIGH (7.5) EPSS: 88.8% 1 exploit
Adobe Coldfusion - Authentica…
CVE-2023-26035 6 months, 2 weeks ago

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

HIGH (7.2) EPSS: 44.3% 1 exploit
ZoneMinder Snapshots - Comman…
CVE-2023-1362 6 months, 2 weeks ago

Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

HIGH (8.4) EPSS: 58.4% 1 exploit
unilogies/bumsys < v2.0.2 - C…
CVE-2023-1880 6 months, 2 weeks ago

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

HIGH (8.3) EPSS: 35.6% 1 exploit
Phpmyfaq v3.1.11 - Cross-Site…
CVE-2023-1698 6 months, 2 weeks ago

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CRITICAL (9.8) EPSS: 93.6% 1 exploit
WAGO - Remote Command Executi…
CVE-2023-1177 6 months, 2 weeks ago

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

CRITICAL (9.3) EPSS: 93.2% 1 exploit
Mlflow <2.2.1 - Local File In…
CVE-2023-1671 6 months, 2 weeks ago

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CRITICAL (9.8) EPSS: 94.3% 1 exploit
Sophos Web Appliance - Remote…
CVE-2023-1892 6 months, 2 weeks ago

Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

HIGH (8.3) EPSS: 74.4% 1 exploit
Sidekiq < 7.0.8 - Cross-Site …
CVE-2023-1719 6 months, 2 weeks ago

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

HIGH (7.5) EPSS: 90.4% 1 exploit
Bitrix Component - Cross-Site…
CVE-2023-24489 6 months, 2 weeks ago

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

CRITICAL (9.8) EPSS: 94.4% 1 exploit
Citrix ShareFile StorageZones…
CVE-2023-32117 6 months, 2 weeks ago

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

CRITICAL (9.8) EPSS: 91.7% 1 exploit
Integrate Google Drive <= 1.1…
CVE-2023-32315 6 months, 2 weeks ago

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

HIGH (8.6) EPSS: 94.4% 1 exploit
Openfire Administration Conso…
CVE-2023-32243 6 months, 2 weeks ago

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

CRITICAL (9.8) EPSS: 92.8% 1 exploit
WordPress Elementor Lite 5.7.…
CVE-2023-32563 6 months, 2 weeks ago

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

HIGH (8.8) EPSS: 92.9% 1 exploit
Ivanti Avalanche - Remote Cod…
CVE-2023-43795 6 months, 2 weeks ago

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.

HIGH (8.6) EPSS: 90.7% 1 exploit
GeoServer WPS - Server Side R…
CVE-2023-40504 6 months, 2 weeks ago

LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the readVideoInfo method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19953.

CRITICAL (9.8) EPSS: 89.6% 1 exploit
LG Simple Editor <= v3.21.0 -…
CVE-2023-47211 6 months, 2 weeks ago

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

CRITICAL (9.1) EPSS: 85.1% 1 exploit
ManageEngine OpManager - Dire…
CVE-2023-47117 6 months, 2 weeks ago

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token of any user by exploiting this ORM Leak vulnerability to leak account password hashes. This vulnerability has been addressed in commit `f931d9d129` which is included in the 1.9.2post0 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

HIGH (7.5) EPSS: 65.9% 1 exploit
Label Studio - Sensitive Info…
CVE-2023-4966 6 months, 2 weeks ago

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CRITICAL (9.4) EPSS: 94.4% 1 exploit
Citrix Bleed - Leaking Sessio…