878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-54236
🔥 KEV Adobe Commerce General ⚡ nuclei
9.1
CRITICAL
EPSS
64.8%
2025 CWE-20 1 PoC

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

CVE-2024-36675
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
44.3%
2024 0 PoCs

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

CVE-2024-33610
Multiple MFPs (multifunction printers) General ⚡ nuclei
9.1
CRITICAL
EPSS
62.3%
2024 CWE-288 3 PoCs

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-4399
cas General ⚡ nuclei
9.1
CRITICAL
EPSS
25.0%
2024 1 PoC

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CVE-2024-41713
🔥 KEV Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
94.1%
2024 5 PoCs

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2025-0282
🔥 KEV Connect Secure General ⚡ nuclei
9.0
CRITICAL
EPSS
94.1%
2025 CWE-121 11 PoCs

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2023-34192
🔥 KEV Software Genérico General ⚡ nuclei
9.0
CRITICAL
EPSS
89.0%
2023 0 PoCs

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CVE-2024-3300
DELMIA Apriso General ⚡ nuclei
9.0
CRITICAL
EPSS
34.7%
2024 CWE-502 1 PoC

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

CVE-2025-48703
🔥 KEV CentOS Web Panel General ⚡ nuclei
9.0
CRITICAL
EPSS
72.6%
2025 CWE-78 3 PoCs

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CVE-2025-23061
Mongoose General ⚡ nuclei
9.0
CRITICAL
EPSS
55.3%
2025 CWE-94 0 PoCs

Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.

CVE-2025-5086
🔥 KEV DELMIA Apriso General ⚡ nuclei
9.0
CRITICAL
EPSS
42.1%
2025 CWE-502 1 PoC

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

CVE-2025-30406
🔥 KEV CentreStack General ⚡ nuclei
9.0
CRITICAL
EPSS
83.4%
2025 CWE-321 6 PoCs

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2024-58136
🔥 KEV Yii General ⚡ nuclei
9.0
CRITICAL
EPSS
57.5%
2024 CWE-424 1 PoC

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

CVE-2020-15148
yii2 General ⚡ nuclei
8.9
HIGH
EPSS
93.4%
2020 CWE-502 2 PoCs

Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.

CVE-2022-37932
Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches General ⚡ nuclei
8.8
HIGH
EPSS
71.6%
2022 1 PoC

A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the vulnerability in Hewlett Packard Enterprise OfficeConnect 1820, 1850 and 1920S Network switches versions: Prior to PT.02.14; Prior to PC.01.22; Prior to PO.01.21; Prior to PD.02.22;

CVE-2023-32563
Avalanche General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 0 PoCs

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2024-7399
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
8.8
HIGH
EPSS
81.3%
2024 CWE-22 2 PoCs

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

CVE-2024-25852
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2024 0 PoCs

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.