9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-30284
Software Genérico General
9.0
CRITICAL
EPSS
14.2%
2022 1 PoC

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network, and thus the CVSS score corresponds to an unrealistic use case. None of the NmapProcess documentation implies that this is an expected use case

CVE-2022-29496
Blynk-Library General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2022-1752
polonel/trudesk General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-1848
erudika/para General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.

CVE-2022-1445
snipe/snipe-it General
9.0
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie.

CVE-2022-3525
librenms/librenms General
9.0
CRITICAL
EPSS
0.0%
2022 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-2063
nocodb/nocodb General
9.0
CRITICAL
EPSS
1.1%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-2112
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2022-2111
inventree/inventree General
9.0
CRITICAL
EPSS
0.4%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

CVE-2024-4142
Artifactory General
9.0
CRITICAL
EPSS
0.8%
2024 CWE-20 1 PoC

An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.

CVE-2023-36998
Software Genérico General
8.9
HIGH
EPSS
0.2%
2023 1 PoC

The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core.

CVE-2021-35213
Orion Platform General
8.9
HIGH
EPSS
0.9%
2021 CWE-284 1 PoC

An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the vulnerability.

CVE-2021-38162
SAP Web Dispatcher General
8.9
HIGH
EPSS
1.8%
2021 CWE-444 1 PoC

SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticated attacker to submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify any information on the server or consume server resources making it temporarily una

CVE-2021-35215
Orion Platform General
8.9
HIGH
EPSS
82.8%
2021 CWE-502 1 PoC

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

CVE-2025-47917
mbedtls General
8.9
HIGH
EPSS
5.2%
2025 CWE-416 1 PoC

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The documentation does not suggest that the function will free that pointer; however, the function does call mbedtls_asn1_free_named_data_list() on that argument, which performs a deep free(). As a result, application code that uses this function (relying only on documented behavior) is likely to still hold pointers to the memory blocks that were fr

CVE-2025-50122
EcoStruxure™ IT Data Center Expert General
8.9
HIGH
EPSS
0.1%
2025 CWE-331 1 PoC

A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.

CVE-2025-66576
Remote Keyboard Desktop General
8.9
HIGH
EPSS
0.6%
2025 CWE-78 1 PoC

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

CVE-2020-15148
yii2 General ⚡ nuclei
8.9
HIGH
EPSS
93.4%
2020 CWE-502 2 PoCs

Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.

CVE-2020-4074
PrestaShop General
8.9
HIGH
EPSS
0.4%
2020 CWE-287 1 PoC

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

CVE-2007-0671
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
55.5%
2007 3 PoCs

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.