164 vulnerabilidades · General · 🔥 KEV · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-10035
🔥 KEV GoAnywhere MFT General ⚡ nuclei
10.0
CRITICAL
EPSS
55.2%
2025 CWE-77 4 PoCs

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVE-2023-35078
🔥 KEV Endpoint Manager Mobile General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 10 PoCs

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

CVE-2021-41277
🔥 KEV metabase General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-200 13 PoCs

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the applicat

CVE-2025-57819
🔥 KEV endpoint General ⚡ nuclei
10.0
CRITICAL
EPSS
76.7%
2025 CWE-89 12 PoCs

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CVE-2024-1709
🔥 KEV ScreenConnect General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-288 15 PoCs

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

CVE-2025-47812
🔥 KEV Wing FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
92.8%
2025 CWE-158 14 PoCs

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

CVE-2019-4716
🔥 KEV Planning Analytics General ⚡ nuclei
10.0
CRITICAL
EPSS
93.4%
2019 3 PoCs

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

CVE-2022-27593
🔥 KEV Photo Station General ⚡ nuclei
10.0
CRITICAL
EPSS
93.1%
2022 CWE-610 0 PoCs

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2023-35082
🔥 KEV EPMM General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 1 PoC

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

CVE-2020-6287
🔥 KEV SAP NetWeaver AS JAVA (LM Configuration Wizard) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2020 8 PoCs

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVE-2025-31324
🔥 KEV SAP NetWeaver (Visual Composer development server) General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2025 CWE-434 20 PoCs

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVE-2024-51378
🔥 KEV Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 5 PoCs

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2020-6207
🔥 KEV SAP Solution Manager (User Experience Monitoring) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.2%
2020 6 PoCs

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

CVE-2023-22527
🔥 KEV Confluence Data Center General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 27 PoCs

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVE-2024-1212
🔥 KEV LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 5 PoCs

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CVE-2023-40044
🔥 KEV WS_FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 CWE-502 6 PoCs

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

CVE-2019-11510
🔥 KEV Software Genérico General ⚡ nuclei
9.9
CRITICAL
EPSS
94.5%
2019 12 PoCs

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVE-2019-10758
🔥 KEV mongo-express General ⚡ nuclei
9.9
CRITICAL
EPSS
94.4%
2019 4 PoCs

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

CVE-2007-3010
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2007 2 PoCs

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.