40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24269
Software Genérico General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2023-49982
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

CVE-2023-4354
Chrome General
8.8
HIGH
EPSS
2.0%
2023 1 PoC

Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2017-18758
Software Genérico General
8.8
HIGH
EPSS
0.6%
2017 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

CVE-2024-28983
Pentaho Business Analytics Server General
8.8
HIGH
EPSS
0.5%
2024 CWE-79 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

CVE-2025-58411
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

CVE-2025-2135
Chrome General
8.8
HIGH
EPSS
2.6%
2025 CWE-843 3 PoCs

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2021-37975
🔥 KEV Chrome General
8.8
HIGH
EPSS
63.0%
2021 2 PoCs

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-5154
LEADTOOLS General
8.8
HIGH
EPSS
0.9%
2019 CWE-122 1 PoC

An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A specially crafted J2K image file can cause an out of bounds write of a null byte in a heap buffer, potentially resulting in code execution. An attack can specially craft a J2K image to trigger this vulnerability.

CVE-2023-32563
Avalanche General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 0 PoCs

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2024-9122
Chrome General
8.8
HIGH
EPSS
15.0%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-44342
Software Genérico General
8.8
HIGH
EPSS
1.3%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

CVE-2024-6989
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-6772
Chrome General
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2023-50222
Ignition General
8.8
HIGH
EPSS
3.2%
2023 CWE-502 1 PoC

Inductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the ResponseParser method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnera

CVE-2021-33528
IE-WL(T)-BL-AP-CL-XX General
8.8
HIGH
EPSS
0.7%
2021 CWE-710 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in the iw_console functionality. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVE-2023-43317
Software Genérico General
8.8
HIGH
EPSS
7.0%
2023 1 PoC

An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

CVE-2024-7399
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
8.8
HIGH
EPSS
81.3%
2024 CWE-22 2 PoCs

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

CVE-2021-41612
Software Genérico General
8.8
HIGH
EPSS
0.6%
2021 1 PoC

An issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly for the subtract instruction, which results in an incorrect value of the carry flag. Any software that relies on this flag may experience corruption in execution.

CVE-2021-40399
WPS Office General
8.8
HIGH
EPSS
0.7%
2021 CWE-416 1 PoC

An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.