40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9479
upKeeper Instant Privilege Access General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

CVE-2023-40151
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-749 1 PoC

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2023-5572
vriteio/vrite General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2020-15149
NodeBB General
9.9
CRITICAL
EPSS
0.4%
2020 CWE-269 2 PoCs

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.

CVE-2023-48777
Elementor Website Builder General ⚡ nuclei
9.9
CRITICAL
EPSS
88.8%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

CVE-2020-6081
3S General
9.9
CRITICAL
EPSS
0.9%
2020 1 PoC

An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2025-27554
ToDesktop General
9.9
CRITICAL
EPSS
0.6%
2025 CWE-94 1 PoC

ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a postinstall script in package.json. No exploitation occurred.

CVE-2023-0022
BusinessObjects Business Intelligence platform (Analysis edition for OLAP) General
9.9
CRITICAL
EPSS
0.8%
2023 CWE-94 1 PoC

SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.

CVE-2025-46093
LiquidFiles General
9.9
CRITICAL
EPSS
0.2%
2025 CWE-732 1 PoC

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

CVE-2025-32579
Sync Posts General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0.

CVE-2025-30911
RTMKit General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

CVE-2025-32682
MapSVG General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through <= 8.6.4.

CVE-2025-26892
Celestial Aura General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

CVE-2025-46157
Software Genérico General
9.9
CRITICAL
EPSS
0.9%
2025 1 PoC

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

CVE-2025-20051
Mattermost General
9.9
CRITICAL
EPSS
0.3%
2025 CWE-22 1 PoC

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate input when patching and duplicating a board, which allows a user to read any arbitrary file on the system via duplicating a specially crafted block in Boards.

CVE-2026-1731
🔥 KEV Remote Support(RS) & Privileged Remote Access(PRA) General
9.9
CRITICAL
EPSS
81.5%
2026 CWE-78 2 PoCs

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

CVE-2025-30220
geoserver General ⚡ nuclei
9.9
CRITICAL
EPSS
13.9%
2025 CWE-611 0 PoCs

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used

CVE-2025-4981
Mattermost General
9.9
CRITICAL
EPSS
1.7%
2025 CWE-427 1 PoC

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenames, potentially leading to remote code execution. The vulnerability impacts instances where file uploads and document search by content is enabled (FileSettings.EnableFileAttachments = true and FileSettings.ExtractContent = true). These configuration settings are enabled by default.

CVE-2025-25279
Mattermost General
9.9
CRITICAL
EPSS
55.7%
2025 CWE-22 2 PoCs

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to properly validate board blocks when importing boards which allows an attacker could read any arbitrary file on the system via importing and exporting a specially crafted import archive in Boards.

CVE-2025-68668
n8n General
9.9
CRITICAL
EPSS
0.1%
2025 CWE-693 1 PoC

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows can exploit this vulnerability to execute arbitrary commands on the host system running n8n, using the same privileges as the n8n process. This issue has been patched in version 2.0.0. Workarounds for this issue involve disabling the Code Node by setting the environment variable NODES_EXCLUDE: "[\"n8n-nodes-base.code\"]", disabling Python support in the Code no