40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-7964
Chrome General
8.8
HIGH
EPSS
1.0%
2024 CWE-416 1 PoC

Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-1389
🔥 KEV TP-Link Archer AX21 (AX1800) General ⚡ nuclei
8.8
HIGH
EPSS
93.5%
2023 5 PoCs

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CVE-2018-3859
Canvas Draw General
8.8
HIGH
EPSS
0.4%
2018 CWE-787 1 PoC

An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3860.

CVE-2025-60785
Software Genérico General
8.8
HIGH
EPSS
0.3%
2025 1 PoC

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted HTML page.

CVE-2024-24350
Software Genérico General
8.8
HIGH
EPSS
1.9%
2024 1 PoC

File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

CVE-2023-27745
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server.

CVE-2020-27228
OpenClinic General
8.8
HIGH
EPSS
0.1%
2020 CWE-276 1 PoC

An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this vulnerability.

CVE-2020-13579
Softmaker Software General
8.8
HIGH
EPSS
3.8%
2020 CWE-190 1 PoC

An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform arithmetic that may overflow which can result in an undersized heap allocation. Later when copying data from the file into this allocation, a heap-based buffer overflow will occur which can corrupt memory. These types of memory corruptions can allow for code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulner

CVE-2023-0164
OrangeScrum General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because the application injects an attacker-controlled parameter into a system function.

CVE-2025-63434
Software Genérico General
8.8
HIGH
EPSS
0.0%
2025 1 PoC

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.

CVE-2023-43236
Software Genérico General
8.8
HIGH
EPSS
1.9%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

CVE-2020-15645
QConvergeConsole General
8.8
HIGH
EPSS
6.0%
2020 CWE-434 2 PoCs

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getFileFromURL method of the GWTTestServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10553.

CVE-2024-32019
netdata General
8.8
HIGH
EPSS
0.6%
2024 CWE-426 9 PoCs

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID bit set. It only runs a restricted set of external commands, but its search paths are supplied by the `PATH` environment variable. This allows an attacker to control where `ndsudo` looks for these commands, which may be a path the attacker has write access to. This may lead to local privilege escalation. This vulnerabili

CVE-2025-56090
Software Genérico General
8.8
HIGH
EPSS
0.2%
2025 3 PoCs

OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain.lua.

CVE-2021-46769
2nd Gen AMD EPYC™ General
8.8
HIGH
EPSS
0.2%
2021 1 PoC

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.

CVE-2023-32221
Todo Backup General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

CVE-2023-2575
EKI-1524 General
8.8
HIGH
EPSS
2.8%
2023 CWE-121 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.

CVE-2021-21862
GPAC General
8.8
HIGH
EPSS
0.4%
2021 CWE-680 1 PoC

Multiple exploitable integer truncation vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an improper memory allocation resulting in a heap-based buffer overflow that causes memory corruption The implementation of the parser used for the “Xtra” FOURCC code is handled. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2024-34221
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVE-2024-44625
Software Genérico General
8.8
HIGH
EPSS
75.1%
2024 2 PoCs

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.