465 vulnerabilidades · General · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2025-53690
🔥 KEV Experience Manager (XM) General
9.0
CRITICAL
EPSS
6.8%
2025 CWE-502 3 PoCs

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

CVE-2025-48703
🔥 KEV CentOS Web Panel General ⚡ nuclei
9.0
CRITICAL
EPSS
72.6%
2025 CWE-78 3 PoCs

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CVE-2025-22457
🔥 KEV Connect Secure General
9.0
CRITICAL
EPSS
53.7%
2025 CWE-121 5 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2025-5086
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.0
CRITICAL
EPSS
42.1%
2025 CWE-502 1 PoC

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

CVE-2025-0282
🔥 KEV Connect Secure General ⚡ nuclei
9.0
CRITICAL
EPSS
94.1%
2025 CWE-121 11 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-58136
🔥 KEV Yii General ⚡ nuclei
9.0
CRITICAL
EPSS
57.5%
2024 CWE-424 1 PoC

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

CVE-2025-30406
🔥 KEV CentreStack General ⚡ nuclei
9.0
CRITICAL
EPSS
83.4%
2025 CWE-321 6 PoCs

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2023-34192
🔥 KEV Software Genérico General ⚡ nuclei
9.0
CRITICAL
EPSS
89.0%
2023 0 PoCs

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CVE-2024-7965
🔥 KEV Chrome General
8.8
HIGH
EPSS
23.8%
2024 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2015-2502
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
21.7%
2015 1 PoC

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

CVE-2025-10585
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-843 3 PoCs

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2025-21043
🔥 KEV Samsung Mobile Devices General
8.8
HIGH
EPSS
4.9%
2025 1 PoC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2024-7399
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
8.8
HIGH
EPSS
81.3%
2024 CWE-22 2 PoCs

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

CVE-2023-5217
🔥 KEV Chrome General
8.8
HIGH
EPSS
4.2%
2023 4 PoCs

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-41993
🔥 KEV macOS General
8.8
HIGH
EPSS
24.2%
2023 4 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-4863
🔥 KEV Chrome General
8.8
HIGH
EPSS
94.1%
2023 14 PoCs

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVE-2025-48543
🔥 KEV Android General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-23529
🔥 KEV iOS and iPadOS General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2013-2729
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
89.6%
2013 1 PoC

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.