40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-7006
Kontrol Lux General
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

CVE-2020-29020
SiteManager General
9.1
CRITICAL
EPSS
0.6%
2020 CWE-284 1 PoC

Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.

CVE-2023-29386
Manager for Icomoon General
9.1
CRITICAL
EPSS
0.3%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

CVE-2021-21014
Magento Commerce General
9.1
CRITICAL
EPSS
0.4%
2021 CWE-434 1 PoC

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.

CVE-2023-41807
Pandora FMS General
9.1
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissions on the system shell. This issue affects Pandora FMS: from 700 through 773.

CVE-2021-21904
Garrett Metal Detectors General
9.1
CRITICAL
EPSS
2.1%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger this vulnerability

CVE-2024-5806
MOVEit Transfer General
9.1
CRITICAL
EPSS
89.9%
2024 CWE-287 2 PoCs

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVE-2024-29643
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVE-2020-4428
🔥 KEV Data Risk Manager General
9.1
CRITICAL
EPSS
92.3%
2020 2 PoCs

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.

CVE-2024-48905
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

CVE-2023-36471
xwiki-commons General
9.1
CRITICAL
EPSS
0.9%
2023 CWE-74 1 PoC

Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println(&quot;Hello from Groovy!&quot;)" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part o

CVE-2024-57763
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.

CVE-2021-34566
750-81xx/xxx-xxxFW General
9.1
CRITICAL
EPSS
0.9%
2021 CWE-120 1 PoC

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

CVE-2024-33661
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

CVE-2025-23099
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

CVE-2024-37404
Connect Secure General
9.1
CRITICAL
EPSS
86.0%
2024 1 PoC

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

CVE-2024-38891
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.

CVE-2025-48706
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted BLE message forces the device to reboot.

CVE-2024-38736
Realtyna Organic IDX plugin General
9.1
CRITICAL
EPSS
1.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.