40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-2034
froxlor/froxlor General
9.1
CRITICAL
EPSS
9.0%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

CVE-2024-38883
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

CVE-2024-41713
🔥 KEV Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
94.1%
2024 5 PoCs

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2024-29643
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVE-2025-56231
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

CVE-2024-37770
Software Genérico General
9.1
CRITICAL
EPSS
11.0%
2024 1 PoC

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2025-39436
I Draw General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.

CVE-2024-46505
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2024 1 PoC

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

CVE-2025-32118
CMP – Coming Soon & Maintenance General
9.1
CRITICAL
EPSS
0.5%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.

CVE-2025-34087
Web General
9.0
CRITICAL
EPSS
72.2%
2025 CWE-78 2 PoCs

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the domain string. These commands are executed on the underlying operating system with the privileges of the Pi-hole service user. This behavior was present in the legacy AdminLTE interface and has since been patched in later versions.

CVE-2021-25387
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.2%
2021 CWE-122 1 PoC

An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-25360
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.3%
2021 CWE-122 2 PoCs

An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2023-25617
Business Objects (Adaptive Job Server) General
9.0
CRITICAL
EPSS
1.7%
2023 CWE-78 1 PoC

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.

CVE-2021-21962
Sealevel General
9.0
CRITICAL
EPSS
2.3%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability.

CVE-2023-0014
NetWeaver ABAP Server and ABAP Platform General
9.0
CRITICAL
EPSS
0.4%
2023 CWE-294 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

CVE-2021-25384
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.2%
2021 CWE-122 1 PoC

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2025-30406
🔥 KEV CentreStack General ⚡ nuclei
9.0
CRITICAL
EPSS
83.4%
2025 CWE-321 6 PoCs

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2014-0783
CENTUM CS 3000 General
9.0
UNKNOWN
EPSS
5.3%
2014 CWE-121 2 PoCs

Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

CVE-2021-27635
SAP NetWeaver AS for JAVA General
9.0
CRITICAL
EPSS
2.1%
2021 1 PoC

SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.

CVE-2021-43616
Software Genérico General
9.0
CRITICAL
EPSS
1.9%
2021 2 PoCs

The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to