9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2017-2794
DMC HTMLFilter General
8.3
HIGH
EPSS
1.0%
2017 1 PoC

An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted PPT file can cause a stack corruption resulting in arbitrary code execution. An attacker can send/provide malicious PPT file to trigger this vulnerability.

CVE-2017-2795
DMC HTMLFilter General
8.3
HIGH
EPSS
0.5%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the Txo functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

CVE-2017-2793
DMC HTMLFilter General
8.3
HIGH
EPSS
0.9%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

CVE-2017-2798
DMC HTMLFilter General
8.3
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability.

CVE-2025-55903
Software Genérico General
8.3
HIGH
EPSS
0.1%
2025 2 PoCs

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

CVE-2025-64057
Software Genérico General
8.3
HIGH
EPSS
0.1%
2025 1 PoC

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

CVE-2025-29471
Software Genérico General
8.3
HIGH
EPSS
20.1%
2025 3 PoCs

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

CVE-2025-59711
Software Genérico General
8.3
HIGH
EPSS
0.6%
2025 1 PoC

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.

CVE-2025-0291
Chrome General
8.3
HIGH
EPSS
12.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2025-36727
Simplehelp General
8.3
HIGH
EPSS
0.1%
2025 CWE-829 1 PoC

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.

CVE-2025-9624
OpenSearch General
8.3
HIGH
EPSS
0.0%
2025 CWE-674 1 PoC

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.

CVE-2020-35801
Software Genérico General
8.3
HIGH
EPSS
1.7%
2020 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects JGS516PE before 2.6.0.48, JGS524Ev2 before 2.6.0.48, JGS524PE before 2.6.0.48, and GS116Ev2 before 2.6.0.48. A TFTP server was found to be active by default. It allows remote authenticated users to update the switch firmware.

CVE-2020-11789
Software Genérico General
8.3
HIGH
EPSS
3.6%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

CVE-2020-6298
SAP Banking Services (Generic Market Data) General
8.3
HIGH
EPSS
0.2%
2020 1 PoC

SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing Authorization Check.

CVE-2020-26921
Software Genérico General
8.3
HIGH
EPSS
0.1%
2020 1 PoC

Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3, and XS724EM before 1.0.1.3.

CVE-2020-6296
SAP NetWeaver (ABAP Server) and ABAP Platform General
8.3
HIGH
EPSS
0.6%
2020 2 PoCs

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

CVE-2020-27652
DiskStation Manager (DSM) General
8.3
HIGH
EPSS
0.4%
2020 CWE-327 2 PoCs

Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.

CVE-2016-8383
AntennaHouse General
8.3
HIGH
EPSS
0.7%
2016 1 PoC

An exploitable heap corruption vulnerability exists in the Doc_GetFontTable functionality of AntennaHouse DMC HTMLFilter. A specially crafted doc file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious doc file to trigger this vulnerability.

CVE-2016-8384
AntennaHouse General
8.3
HIGH
EPSS
0.4%
2016 1 PoC

An exploitable heap corruption vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter.

CVE-2018-1251
Dell EMC Unity General
8.3
HIGH
EPSS
0.3%
2018 1 PoC

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.