9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-30166
P2/Z2/P3/Z3 IP camera firmware General
7.2
HIGH
EPSS
6.6%
2021 CWE-78 1 PoC

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

CVE-2021-33547
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42382
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVE-2021-25500
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.0%
2021 CWE-20 1 PoC

A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

CVE-2021-33551
E2 Series General
7.2
HIGH
EPSS
84.0%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2025-4687
RMS General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and registers to the platform directly, they are added to the attackers company without their knowledge. The victims account and their company can then be managed by the attacker.This issue affects RMS: before 5.7.

CVE-2025-63215
Software Genérico General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

CVE-2025-46612
Software Genérico General
7.2
HIGH
EPSS
1.6%
2025 1 PoC

The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.jsp unrestricted file upload. To exploit this, the attacker must login to the administrator console (default credentials are weak and easily guessable) and upload a JSP file via the Panel Designer dashboard.

CVE-2025-66644
🔥 KEV ArrayOS AG General
7.2
HIGH
EPSS
1.2%
2025 CWE-78 1 PoC

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

CVE-2025-22510
WC Price History for Omnibus General
7.2
HIGH
EPSS
14.9%
2025 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Object Injection.This issue affects WC Price History for Omnibus: from n/a through <= 2.1.4.

CVE-2025-50891
server-side backend for Site Tracking General
7.2
HIGH
EPSS
0.1%
2025 CWE-79 1 PoC

The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).

CVE-2025-60787
Software Genérico General
7.2
HIGH
EPSS
65.3%
2025 1 PoC

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.

CVE-2025-3945
Niagara Framework General
7.2
HIGH
EPSS
0.4%
2025 CWE-88 1 PoC

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1, before 4.10.11. Tridium recommends upgrading to Niagara Framework and Enterprise Security versions 4.14.2u2, 4.15.u1, or 4.10u.11.

CVE-2025-61482
Software Genérico General
7.2
HIGH
EPSS
0.0%
2025 1 PoC

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By hooking into app crypto routines and intercepting decryption paths, attacker can recover plaintext secrets, enabling generation of valid one-time passwords, and bypassing authentication for enrolled accounts.

CVE-2025-32813
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
11.2%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

CVE-2025-36729
M!DGE2 General
7.2
HIGH
EPSS
0.1%
2025 CWE-269 1 PoC

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master admin password. This vulnerability also allows the user to give themselves shell access with the root gid.

CVE-2025-22962
Software Genérico General
7.2
HIGH
EPSS
1.1%
2025 1 PoC

A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json endpoint, enabling arbitrary command execution on the underlying system. This vulnerability can lead to full system compromise, including unauthorized access, privilege escalation, and potentially full device takeover.

CVE-2025-46123
Software Genérico General
7.2
HIGH
EPSS
1.4%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefore triggers uncontrolled format-string processing and enables remote code execution on the controller.

CVE-2025-63220
Software Genérico General
7.2
HIGH
EPSS
0.2%
2025 1 PoC

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

CVE-2025-41673
mbNET.mini General
7.2
HIGH
EPSS
0.2%
2025 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command.