9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-24516
Software Genérico General
8.8
HIGH
EPSS
0.1%
2026 2 PoCs

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without adequate input validation. While the code validates that artifacts exist in the validInvestigationArtifacts map, it fails to sanitize the actual command content after the "command:" prefix. This allows an attacker who can control metadata responses to inject and execute arbitrary OS comm

CVE-2026-42372
DIR-605L Firmware General
8.8
HIGH
EPSS
0.0%
2026 CWE-798 1 PoC

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell with full administrative control. The device has reached End-of-Life (EOL) and will not receive patche

CVE-2026-30784
RustDesk Server General
8.8
HIGH
EPSS
0.4%
2026 CWE-862 1 PoC

Missing Authorization, Missing Authentication for Critical Function vulnerability in rustdesk-server RustDesk Server rustdesk-server, rustdesk-server-pro on hbbs/hbbr on all server platforms (Rendezvous server (hbbs), relay server (hbbr) modules) allows Privilege Abuse. This vulnerability is associated with program files src/rendezvous_server.Rs, src/relay_server.Rs and program routines handle_punch_hole_request(), RegisterPeer handler, relay forwarding. This issue affects RustDesk Server: through 1.7.5, through 1.1.15.

CVE-2026-0908
Chrome General
8.8
HIGH
EPSS
0.0%
2026 CWE-416 1 PoC

Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2023-27216
Software Genérico General
8.8
HIGH
EPSS
27.8%
2023 3 PoCs

An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

CVE-2023-22299
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-78 1 PoC

An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-43242
Software Genérico General
8.8
HIGH
EPSS
2.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.

CVE-2023-43237
Software Genérico General
8.8
HIGH
EPSS
57.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

CVE-2023-33131
Microsoft Office 2019 General
8.8
HIGH
EPSS
2.7%
2023 1 PoC

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-24217
Software Genérico General
8.8
HIGH
EPSS
4.9%
2023 1 PoC

AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.

CVE-2023-2573
EKI-1524 General
8.8
HIGH
EPSS
1.4%
2023 CWE-78 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-2936
Chrome General
8.8
HIGH
EPSS
9.4%
2023 1 PoC

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-47352
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

CVE-2023-4352
Chrome General
8.8
HIGH
EPSS
1.4%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-50219
Ignition General
8.8
HIGH
EPSS
8.9%
2023 CWE-502 1 PoC

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the RunQuery class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21625.

CVE-2023-2575
EKI-1524 General
8.8
HIGH
EPSS
2.8%
2023 CWE-121 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-32221
Todo Backup General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

CVE-2023-43236
Software Genérico General
8.8
HIGH
EPSS
1.9%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

CVE-2023-0164
OrangeScrum General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.

CVE-2023-27745
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.