40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2016-20037
xWPE General
8.6
HIGH
EPSS
0.0%
2016 CWE-787 1 PoC

xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can craft malicious command-line arguments with 262 bytes of junk data followed by shellcode to overwrite the instruction pointer and achieve code execution or denial of service.

CVE-2018-25303
Allok Video to DVD Burner General
8.6
HIGH
EPSS
0.0%
2018 CWE-121 1 PoC

Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input string with 780 bytes of junk data followed by SEH chain pointers and shellcode, then paste it into the License Name field during registration to achieve code execution.

CVE-2025-7766
Provisioning Manager General
8.6
HIGH
EPSS
0.3%
2025 CWE-611 2 PoCs

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.

CVE-2024-31850
Arc General ⚡ nuclei
8.6
HIGH
EPSS
89.9%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

CVE-2009-20008
Green Dam Youth Escort General
8.6
HIGH
EPSS
46.3%
2009 CWE-121 4 PoCs

Green Dam Youth Escort version 3.17 is vulnerable to a stack-based buffer overflow when processing overly long URLs. The flaw resides in the URL filtering component, which fails to properly validate input length before copying user-supplied data into a fixed-size buffer. A remote attacker can exploit this vulnerability by enticing a user to visit a specially crafted webpage containing a long URL, resulting in arbitrary code execution.

CVE-2019-25681
Xlight General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration to trigger a buffer overflow that corrupts the SEH chain and enables potential code execution.

CVE-2016-20044
PInfo General
8.6
HIGH
EPSS
0.0%
2016 CWE-787 1 PoC

PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -m parameter. Attackers can craft a malicious input string with 564 bytes of padding followed by a return address to overwrite the instruction pointer and execute shellcode with user privileges.

CVE-2024-34361
pi-hole General
8.6
HIGH
EPSS
58.2%
2024 CWE-918 1 PoC

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

CVE-2021-23427
elFinder.NetCore General
8.6
HIGH
EPSS
0.6%
2021 1 PoC

This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

CVE-2023-41954
ProfilePress General ⚡ nuclei
8.6
HIGH
EPSS
9.8%
2023 CWE-269 0 PoCs

Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

CVE-2025-12816
node-forge General
8.6
HIGH
EPSS
0.1%
2025 2 PoCs

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

CVE-2022-32760
iota All-In-One Security Kit General
8.6
HIGH
EPSS
0.5%
2022 CWE-489 1 PoC

A denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2024-36117
reposilite General ⚡ nuclei
8.6
HIGH
EPSS
74.1%
2024 CWE-22 0 PoCs

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.

CVE-2025-5309
Remote support & Privileged Remote Access General
8.6
HIGH
EPSS
1.4%
2025 CWE-94 1 PoC

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

CVE-2023-53965
SOUND4 Server Service General
8.6
HIGH
EPSS
0.0%
2023 CWE-428 2 PoCs

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during service startup.

CVE-2016-20047
EKG Gadu General
8.6
HIGH
EPSS
0.0%
2016 CWE-787 1 PoC

EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local attackers to execute arbitrary code by supplying an oversized username string. Attackers can trigger the overflow in the strlcpy function by passing a crafted buffer exceeding 258 bytes to overwrite the instruction pointer and execute shellcode with user privileges.

CVE-2016-20040
Texas Instrument Emulator General
8.6
HIGH
EPSS
0.0%
2016 CWE-22 1 PoC

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.

CVE-2025-34197
Print Virtual Appliance Host General
8.6
HIGH
EPSS
0.0%
2025 CWE-798 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) contain an undocumented local user account named ubuntu with a preset password and a sudoers entry granting that account passwordless root privileges (ubuntu ALL=(ALL) NOPASSWD: ALL). Anyone who knows the hardcoded password can obtain root privileges via local console or equivalent administrative access, enabling local privilege escalation. This vulnerability has been identified by the vendor as: V-2024-010 — Hardcoded Linux Password. NOTE: The patch

CVE-2019-25609
Server General
8.6
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration field that allows local attackers to overwrite structured exception handling pointers. Attackers can inject alphanumeric encoded shellcode through the Log Directory field to trigger an SEH exception handler and execute arbitrary code with application privileges.

CVE-2024-21544
spatie/browsershot General
8.6
HIGH
EPSS
0.2%
2024 CWE-20 1 PoC

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.