40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-50223
Ignition General
8.8
HIGH
EPSS
49.0%
2023 CWE-502 1 PoC

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExtendedDocumentCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI

CVE-2025-2073
ChromeOS General
8.8
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

CVE-2023-37569
Emagic Data Center Management Suite General
8.8
HIGH
EPSS
53.1%
2023 CWE-78 1 PoC

This vulnerability exists in ESDS Emagic Data Center Management Suit due to lack of input sanitization in its Ping component. A remote authenticated attacker could exploit this by injecting OS commands on the targeted system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on targeted system.

CVE-2024-5838
Chrome General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-41969
CC100 0751-9x01 General
8.8
HIGH
EPSS
1.2%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

CVE-2023-27826
Software Genérico General
8.8
HIGH
EPSS
17.3%
2023 1 PoC

SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

CVE-2018-17463
🔥 KEV Chrome General
8.8
HIGH
EPSS
92.2%
2018 3 PoCs

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2023-36899
Microsoft .NET Framework 4.8 General
8.8
HIGH
EPSS
70.0%
2023 CWE-20 2 PoCs

ASP.NET Elevation of Privilege Vulnerability

CVE-2023-46522
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.

CVE-2024-51023
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2021-21224
🔥 KEV Chrome General
8.8
HIGH
EPSS
46.9%
2021 2 PoCs

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2023-25266
Software Genérico General
8.8
HIGH
EPSS
5.7%
2023 1 PoC

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).

CVE-2024-40500
Software Genérico General
8.8
HIGH
EPSS
2.1%
2024 2 PoCs

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component.

CVE-2025-58411
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

CVE-2024-48271
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

CVE-2024-55587
Software Genérico General
8.8
HIGH
EPSS
37.3%
2024 1 PoC

python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

CVE-2018-16739
Software Genérico General
8.8
HIGH
EPSS
0.2%
2018 1 PoC

An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.

CVE-2025-0593
SICK Lector8xx General
8.8
HIGH
EPSS
0.1%
2025 CWE-77 1 PoC

The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.

CVE-2024-27655
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.