40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-13546
SoftMaker General
8.8
HIGH
EPSS
0.3%
2020 CWE-190 1 PoC

In SoftMaker Software GmbH SoftMaker Office TextMaker 2021 (revision 1014), a specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability.

CVE-2023-33131
Microsoft Office 2019 General
8.8
HIGH
EPSS
2.7%
2023 1 PoC

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-2813
AC15 General
8.8
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257668. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-24328
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
84.4%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

CVE-2021-45960
Software Genérico General
8.8
HIGH
EPSS
0.3%
2021 4 PoCs

In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory).

CVE-2021-40396
Software Genérico General
8.8
HIGH
EPSS
0.0%
2021 CWE-276 1 PoC

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-21411
Skype for Consumer General
8.8
HIGH
EPSS
5.0%
2024 CWE-453 1 PoC

Skype for Consumer Remote Code Execution Vulnerability

CVE-2024-45982
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

CVE-2023-27216
Software Genérico General
8.8
HIGH
EPSS
27.8%
2023 3 PoCs

An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

CVE-2020-6150
Pixar General
8.8
HIGH
EPSS
0.2%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompression heap overflow.

CVE-2021-21224
🔥 KEV Chrome General
8.8
HIGH
EPSS
46.9%
2021 2 PoCs

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2024-0692
Security Event Manager General ⚡ nuclei
8.8
HIGH
EPSS
78.3%
2024 CWE-502 0 PoCs

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

CVE-2026-0908
Chrome General
8.8
HIGH
EPSS
0.0%
2026 CWE-416 1 PoC

Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2022-0511
Firefox General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97.

CVE-2022-2333
SoftMaster General
8.8
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.

CVE-2021-21846
GPAC General
8.8
HIGH
EPSS
0.5%
2021 CWE-680 2 PoCs

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input in “stsz” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2024-46625
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2019-5058
SDL General
8.8
HIGH
EPSS
1.0%
2019 CWE-122 1 PoC

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

CVE-2025-3067
Chrome General
8.8
HIGH
EPSS
0.2%
2025 1 PoC

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted app. (Chromium security severity: Medium)

CVE-2024-46433
Software Genérico General
8.8
HIGH
EPSS
1.0%
2024 1 PoC

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.