40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-34491
MailEssentials General
8.8
HIGH
EPSS
1.2%
2025 CWE-502 1 PoC

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.

CVE-2024-1670
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2020-9046
Kantech EntraPass Security Management Software Special Edition versions 8.22 and prior General
8.8
HIGH
EPSS
0.0%
2020 CWE-284 1 PoC

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.

CVE-2025-34119
EasyCafe Server General
8.8
HIGH
EPSS
29.6%
2025 CWE-668 2 PoCs

A remote file disclosure vulnerability exists in EasyCafe Server 2.2.14, exploitable by unauthenticated remote attackers via TCP port 831. The server listens for a custom protocol where opcode 0x43 can be used to request arbitrary files by absolute path. If the file exists and is accessible, its content is returned without authentication. This flaw allows attackers to retrieve sensitive files such as system configuration, password files, or application data.

CVE-2025-32059
Infotainment system ECU General
8.8
HIGH
EPSS
0.0%
2025 CWE-121 2 PoCs

The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper layer L2CAP channel. An attacker can leverage this vulnerability to obtain remote code execution on the Infotainment ECU with root privileges. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2023-43318
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 3 PoCs

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

CVE-2019-3398
🔥 KEV Confluence General ⚡ nuclei
8.8
HIGH
EPSS
93.9%
2019 5 PoCs

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the f

CVE-2024-25386
Software Genérico General
8.8
HIGH
EPSS
9.5%
2024 1 PoC

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

CVE-2024-12695
Chrome General
8.8
HIGH
EPSS
2.2%
2024 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-27756
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

CVE-2025-32976
Software Genérico General
8.8
HIGH
EPSS
0.5%
2025 3 PoCs

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows authenticated users to bypass TOTP-based 2FA requirements. The vulnerability exists in the 2FA validation process and can be exploited to gain elevated access.

CVE-2024-28984
Pentaho Business Analytics Server General
8.8
HIGH
EPSS
0.4%
2024 CWE-79 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

CVE-2025-57434
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows.

CVE-2021-27256
R7800 General
8.8
HIGH
EPSS
0.6%
2021 CWE-78 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_save.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12355.

CVE-2023-43239
Software Genérico General
8.8
HIGH
EPSS
57.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

CVE-2024-34448
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

CVE-2017-2821
Perceptive Document Filters General
8.8
HIGH
EPSS
1.7%
2017 1 PoC

An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code execution.

CVE-2021-33532
IE-WL(T)-BL-AP-CL-XX General
8.8
HIGH
EPSS
5.6%
2021 CWE-78 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVE-2025-0995
Chrome General
8.8
HIGH
EPSS
0.3%
2025 CWE-416 1 PoC

Use after free in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-8638
Chrome General
8.8
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)