40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-50944
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.

CVE-2023-39780
🔥 KEV RT-AX55 General
8.8
HIGH
EPSS
41.1%
2023 CWE-78 1 PoC

On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348.

CVE-2024-24328
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
84.4%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

CVE-2014-9495
Software Genérico General
8.8
HIGH
EPSS
3.5%
2014 1 PoC

Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers to execute arbitrary code via a "very wide interlaced" PNG image.

CVE-2025-30772
WPC Smart Upsell Funnel for WooCommerce General
8.8
HIGH
EPSS
0.5%
2025 CWE-862 1 PoC

Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects WPC Smart Upsell Funnel for WooCommerce: from n/a through <= 3.0.4.

CVE-2025-6558
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.2%
2025 CWE-20 3 PoCs

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2025-5280
Chrome General
8.8
HIGH
EPSS
0.6%
2025 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-22612
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.

CVE-2025-56084
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp.lua.

CVE-2023-37213
SYnergy Fingerprint Terminals General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'

CVE-2023-46525
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVE-2021-21900
LibreCAD General
8.8
HIGH
EPSS
0.3%
2021 CWE-416 1 PoC

A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-25251
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

CVE-2025-56087
Software Genérico General
8.8
HIGH
EPSS
0.1%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump.lua.

CVE-2024-5847
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVE-2023-43478
Smart Modem Gen 2 (Arcadyan LH1000) General
8.8
HIGH
EPSS
4.1%
2023 1 PoC

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 

CVE-2021-33530
IE-WL(T)-BL-AP-CL-XX General
8.8
HIGH
EPSS
5.1%
2021 CWE-78 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

CVE-2021-21836
GPAC Project General
8.8
HIGH
EPSS
0.2%
2021 CWE-680 1 PoC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input using the “ctts” FOURCC code can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2017-18758
Software Genérico General
8.8
HIGH
EPSS
0.6%
2017 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

CVE-2021-26411
🔥 KEV Internet Explorer 9 General
8.8
HIGH
EPSS
92.5%
2021 1 PoC

Internet Explorer Memory Corruption Vulnerability