2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-43605
OpENer General
10.0
CRITICAL
EPSS
5.5%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVE-2022-32454
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
5.0%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-21806
Eufy Homebase 2 General
10.0
CRITICAL
EPSS
1.8%
2022 CWE-368 1 PoC

A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.

CVE-2015-2079
Usermin General
9.9
CRITICAL
EPSS
2.8%
2015 CWE-96 1 PoC

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

CVE-2026-1470
Software Genérico General
9.9
CRITICAL
EPSS
1.9%
2026 CWE-95 1 PoC

n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operati

CVE-2026-22907
TDC-X401GL General
9.9
CRITICAL
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

CVE-2026-1731
🔥 KEV Remote Support(RS) & Privileged Remote Access(PRA) General
9.9
CRITICAL
EPSS
81.5%
2026 CWE-78 2 PoCs

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CVE-2026-30269
Software Genérico General
9.9
CRITICAL
EPSS
0.0%
2026 1 PoC

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privilege escalation to high-privileged roles.

CVE-2023-4159
omeka/omeka-s General
9.9
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.

CVE-2023-25616
Business Objects Business Intelligence Platform (CMC) General
9.9
CRITICAL
EPSS
0.6%
2023 CWE-74 1 PoC

In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack could highly impact the confidentiality, Integrity, and Availability of the system.

CVE-2023-0022
BusinessObjects Business Intelligence platform (Analysis edition for OLAP) General
9.9
CRITICAL
EPSS
0.8%
2023 CWE-94 1 PoC

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.

CVE-2023-48777
Elementor Website Builder General ⚡ nuclei
9.9
CRITICAL
EPSS
88.8%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

CVE-2023-47840
Qode Essential Addons General
9.9
CRITICAL
EPSS
21.2%
2023 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.

CVE-2023-53739
Tinycontrol LAN Controller v General
9.9
CRITICAL
EPSS
0.3%
2023 CWE-260 2 PoCs

Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.

CVE-2023-3710
PM23/43 General ⚡ nuclei
9.9
CRITICAL
EPSS
91.7%
2023 CWE-20 3 PoCs

Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-0671
froxlor/froxlor General
9.9
CRITICAL
EPSS
0.5%
2023 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.

CVE-2024-27972
WP Fusion Lite General
9.9
CRITICAL
EPSS
38.2%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.

CVE-2024-24707
Cwicly General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

CVE-2024-37361
Pentaho Data Integration & Analytics General
9.9
CRITICAL
EPSS
0.4%
2024 CWE-502 1 PoC

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to le

CVE-2024-52429
WP Quick Setup General
9.9
CRITICAL
EPSS
41.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.