14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2018-25140
Thermal Traffic Cameras General
9.3
CRITICAL
EPSS
0.2%
2018 CWE-306 2 PoCs

FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

CVE-2010-20103
ProFTPD (Professional FTP Daemon) General
9.3
CRITICAL
EPSS
85.1%
2010 CWE-912 3 PoCs

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.

CVE-2010-20122
Xftp FTP Client General
9.3
CRITICAL
EPSS
58.6%
2010 CWE-121 3 PoCs

Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system.

CVE-2010-20121
EasyFTP Server General
9.3
CRITICAL
EPSS
68.6%
2010 CWE-121 7 PoCs

EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change Working Directory) command, the server fails to properly validate the length of the input string, allowing attackers to overwrite memory on the stack. This flaw enables remote code execution without authentication, as EasyFTP allows anonymous access by default. The vulnerability was resolved in version 1.7.0.12, after which the product was renamed “UplusFtp.”

CVE-2010-20049
LeapFTP General
9.3
CRITICAL
EPSS
54.2%
2010 CWE-121 3 PoCs

LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured Exception Handler (SEH) chain. This allows an attacker operating a malicious FTP server to execute arbitrary code on the victim’s machine when the file is listed or downloaded.

CVE-2011-10032
ForceControl General
9.3
CRITICAL
EPSS
64.8%
2011 CWE-121 3 PoCs

Sunway ForceControl version 6.1 SP3 and earlier contains a stack-based buffer overflow vulnerability in the SNMP NetDBServer service, which listens on TCP port 2001. The flaw is triggered when the service receives a specially crafted packet using opcode 0x57 with an overly long payload. Due to improper bounds checking during packet parsing, attacker-controlled data overwrites the Structured Exception Handler (SEH), allowing arbitrary code execution in the context of the service. This vulnerability can be exploited remotely without authentication and may lead to full system compromise on affect

CVE-2011-10015
Studio General
9.3
CRITICAL
EPSS
4.2%
2011 CWE-121 5 PoCs

Cytel Studio version 9.0 and earlier is vulnerable to a stack-based buffer overflow triggered by parsing a malformed .CY3 file. The vulnerability occurs when the application copies user-controlled strings into a fixed-size stack buffer (256 bytes) without proper bounds checking. Exploitation allows arbitrary code execution when the crafted file is opened.

CVE-2011-10016
Netzip Classic General
9.3
CRITICAL
EPSS
9.7%
2011 CWE-121 3 PoCs

Real Networks Netzip Classic version 7.5.1.86 is vulnerable to a stack-based buffer overflow when parsing a specially crafted ZIP archive. The vulnerability is triggered when the application attempts to process a file name within the archive that exceeds the expected buffer size. Exploitation allows arbitrary code execution under the context of the victim user when the ZIP file is opened.

CVE-2022-4980
Crypto Application Server (CAS) General
9.3
CRITICAL
EPSS
0.8%
2022 CWE-306 2 PoCs

General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation page and create a new administrative account remotely. By gaining admin privileges, the attacker can change the ATM configuration resulting in redirected funds. Public vendor advisories and multiple independent writeups describe the vulnerability as a call to the page used for ini

CVE-2022-1996
emicklei/go-restful General
9.3
CRITICAL
EPSS
1.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVE-2022-50691
MiniDVBLinux General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-78 1 PoC

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.

CVE-2022-0990
janeczku/calibre-web General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

CVE-2022-27660
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.5%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-21817
Software Genérico General
9.3
CRITICAL
EPSS
0.9%
2022 1 PoC

NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

CVE-2022-4978
Remote Control Collection Server General
9.3
CRITICAL
EPSS
32.4%
2022 CWE-306 1 PoC

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same network can issue a sequence of keystroke commands to launch a system shell and execute arbitrary commands, resulting in full system compromise.

CVE-2022-27185
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-50919
Tdarr General
9.3
CRITICAL
EPSS
1.5%
2022 CWE-78 1 PoC

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

CVE-2022-50796
Impact/Pulse/First General
9.3
CRITICAL
EPSS
1.1%
2022 CWE-22 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

CVE-2022-1212
mruby/mruby General
9.3
CRITICAL
EPSS
0.9%
2022 CWE-416 1 PoC

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-1543
erudika/scoold General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-130 1 PoC

Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.