40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-43237
Software Genérico General
8.8
HIGH
EPSS
57.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

CVE-2023-22299
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-78 1 PoC

An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2024-12382
Chrome General
8.8
HIGH
EPSS
12.6%
2024 CWE-416 1 PoC

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-43242
Software Genérico General
8.8
HIGH
EPSS
2.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.

CVE-2018-3887
Computerinsel Photoline General
8.8
HIGH
EPSS
0.6%
2018 1 PoC

A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.

CVE-2025-31129
jooby General
8.8
HIGH
EPSS
0.5%
2025 CWE-502 1 PoC

Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).

CVE-2021-33531
IE-WL(T)-BL-AP-CL-XX General
8.8
HIGH
EPSS
0.2%
2021 CWE-798 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts. An attacker can send diagnostic scripts while authenticated as a low privilege user to trigger this vulnerability.

CVE-2021-4080
crater-invoice/crater General
8.8
HIGH
EPSS
0.4%
2021 CWE-434 1 PoC

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2024-25251
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

CVE-2020-13552
Advantech General
8.8
HIGH
EPSS
0.1%
2020 CWE-276 1 PoC

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

CVE-2020-16009
🔥 KEV Chrome General
8.8
HIGH
EPSS
84.4%
2020 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-27256
R7800 General
8.8
HIGH
EPSS
0.6%
2021 CWE-78 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_save.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12355.

CVE-2019-5045
NitroPDF General
8.8
HIGH
EPSS
0.1%
2019 CWE-122 1 PoC

A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

CVE-2022-43938
Pentaho Business Analytics Server General
8.8
HIGH
EPSS
4.5%
2022 CWE-96 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. 

CVE-2025-58411
Graphics DDK General
8.8
HIGH
EPSS
0.0%
2025 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

CVE-2019-3651
Advanced Threat Defense (ATD) General
8.8
HIGH
EPSS
0.5%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credentials, which were too permissive.

CVE-2019-20706
Software Genérico General
8.8
HIGH
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

CVE-2021-21847
GPAC General
8.8
HIGH
EPSS
0.3%
2021 CWE-680 2 PoCs

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stts” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2024-0750
Firefox General
8.8
HIGH
EPSS
1.5%
2024 1 PoC

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.