40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9494
CP210 VCP Win 2k General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2018-25307
SysGauge Pro General
8.6
HIGH
EPSS
0.0%
2018 CWE-120 1 PoC

SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrary code with application privileges.

CVE-2021-3837
openwhyd/openwhyd General
8.6
HIGH
EPSS
0.1%
2021 CWE-285 1 PoC

openwhyd is vulnerable to Improper Authorization

CVE-2022-1026
Multifunction Printer Net Viewer General ⚡ nuclei
8.6
HIGH
EPSS
86.8%
2022 CWE-522 2 PoCs

Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

CVE-2025-9961
AX10 V1/V1.2/V2/V2.6/V3/V3.6 General
8.6
HIGH
EPSS
0.2%
2025 CWE-120 1 PoC

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6: before 1.3.11.

CVE-2025-50850
Software Genérico General
8.6
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.

CVE-2020-28590
Slic3r General
8.6
HIGH
EPSS
0.3%
2020 CWE-20 2 PoCs

An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-27662
KT-1 General
8.6
HIGH
EPSS
0.2%
2021 CWE-294 1 PoC

The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker can record and replay TCP packets. This issue affects Johnson Controls KT-1 all versions up to and including 3.01

CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVE-2023-30990
i General
8.6
HIGH
EPSS
0.2%
2023 CWE-94 1 PoC

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.

CVE-2021-20987
EtherNet/IP Core V2 General
8.6
HIGH
EPSS
0.4%
2021 CWE-787 1 PoC

A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.

CVE-2021-23452
x-assign General
8.6
HIGH
EPSS
0.6%
2021 1 PoC

This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.

CVE-2020-28450
decal General
8.6
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package decal. The vulnerability is in the extend function.

CVE-2024-5716
Unified SecOps Platform General
8.6
HIGH
EPSS
0.5%
2024 CWE-307 1 PoC

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password reset mechanism. The issue results from the lack of restriction of excessive authentication attempts. An attacker can leverage this vulnerability to reset a user's password and bypass authentication on the system. Was ZDI-CAN-24164.

CVE-2021-3770
vim/vim General
8.6
HIGH
EPSS
0.3%
2021 CWE-122 2 PoCs

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-43799
zulip General
8.6
HIGH
EPSS
5.3%
2021 CWE-338 1 PoC

Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's default "cookie" which protects this port is generated using a weak PRNG, which limits the entropy of the password to at most 36 bits; in practicality, the seed for the randomizer is biased, resulting in a

CVE-2023-45612
Ktor General
8.6
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CVE-2023-3722
Aura Device Services General ⚡ nuclei
8.6
HIGH
EPSS
54.6%
2023 CWE-434 1 PoC

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2025-51087
Software Genérico General
8.6
HIGH
EPSS
0.4%
2025 1 PoC

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow.