2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-23061
Mongoose General ⚡ nuclei
9.0
CRITICAL
EPSS
55.3%
2025 CWE-94 0 PoCs

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

CVE-2025-48703
🔥 KEV CentOS Web Panel General ⚡ nuclei
9.0
CRITICAL
EPSS
72.6%
2025 CWE-78 3 PoCs

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CVE-2025-27590
Oxidized Web General
9.0
CRITICAL
EPSS
13.4%
2025 CWE-22 1 PoC

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

CVE-2025-30406
🔥 KEV CentreStack General ⚡ nuclei
9.0
CRITICAL
EPSS
83.4%
2025 CWE-321 6 PoCs

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2025-0282
🔥 KEV Connect Secure General ⚡ nuclei
9.0
CRITICAL
EPSS
94.1%
2025 CWE-121 11 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2025-22457
🔥 KEV Connect Secure General
9.0
CRITICAL
EPSS
53.7%
2025 CWE-121 5 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2025-53690
🔥 KEV Experience Manager (XM) General
9.0
CRITICAL
EPSS
6.8%
2025 CWE-502 3 PoCs

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.

CVE-2025-26206
Software Genérico General
9.0
CRITICAL
EPSS
0.4%
2025 1 PoC

Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component

CVE-2020-6284
SAP NetWeaver (Knowledge Management) General
9.0
CRITICAL
EPSS
0.9%
2020 1 PoC

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.

CVE-2020-10071
zephyr General
9.0
CRITICAL
EPSS
13.9%
2020 CWE-120 2 PoCs

The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

CVE-2020-12029
FactoryTalk View SE General
9.0
CRITICAL
EPSS
24.6%
2020 CWE-20 1 PoC

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

CVE-2020-10022
zephyr General
9.0
CRITICAL
EPSS
1.7%
2020 CWE-120 1 PoC

A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions. version 2.2.0 and later versions.

CVE-2020-10070
zephyr General
9.0
CRITICAL
EPSS
6.5%
2020 CWE-120 2 PoCs

In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

CVE-2020-7293
McAfee Web Gateway (MWG) General
9.0
CRITICAL
EPSS
0.1%
2020 CWE-287 1 PoC

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.

CVE-2020-29026
GateManager General
9.0
CRITICAL
EPSS
0.3%
2020 CWE-22 1 PoC

A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system. This issue affects: GateManager all versions prior to 9.2c.

CVE-2020-10062
zephyr General
9.0
CRITICAL
EPSS
5.8%
2020 CWE-193 2 PoCs

An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.

CVE-2018-4054
Pixar Renderman General
9.0
CRITICAL
EPSS
0.0%
2018 1 PoC

A local privilege escalation vulnerability exists in the install helper tool of the Mac OS X version of Pixar Renderman, version 22.2.0. A user with local access can use this vulnerability to escalate their privileges to root. An attacker would need local access to the machine to successfully exploit this flaw.

CVE-2018-3947
Yi Technology General
9.0
CRITICAL
EPSS
0.5%
2018 1 PoC

An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit this vulnerability.

CVE-2018-3934
Yi Technology General
9.0
CRITICAL
EPSS
1.7%
2018 1 PoC

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability.

CVE-2022-0939
janeczku/calibre-web General
9.0
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.