40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-30284
Software Genérico General
8.6
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2021-3517
libxml2 General
8.6
HIGH
EPSS
0.1%
2021 CWE-787 4 PoCs

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.

CVE-2026-27182
Saturn Remote Mouse Server General
8.6
HIGH
EPSS
0.1%
2026 CWE-306 1 PoC

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

CVE-2024-9492
Flash Programming Utility General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2022-31188
cvat General
8.6
HIGH
EPSS
35.7%
2022 CWE-918 2 PoCs

CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were found to be subject to a Server-side request forgery (SSRF) vulnerability. Validation has been added to urls used in the affected code path in version 2.0.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2020-28590
Slic3r General
8.6
HIGH
EPSS
0.3%
2020 CWE-20 2 PoCs

An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-58338
Flamingo XL General
8.6
HIGH
EPSS
0.1%
2024 CWE-78 2 PoCs

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.

CVE-2025-32367
face recognition application General
8.6
HIGH
EPSS
0.3%
2025 CWE-425 1 PoC

The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the number 4.0.8 was used for both the unpatched and patched versions.

CVE-2025-5459
Puppet Enterprise General
8.6
HIGH
EPSS
0.3%
2025 CWE-78 1 PoC

A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions 2018.1.8 through 2023.8.3 and 2025.3 and has been resolved in versions 2023.8.4 and 2025.4.0.

CVE-2025-30066
🔥 KEV changed-files General
8.6
HIGH
EPSS
91.8%
2025 CWE-506 2 PoCs

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

CVE-2024-35340
Software Genérico General
8.6
HIGH
EPSS
2.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

CVE-2026-8077
CashDro 3 Administration Panel General
8.6
HIGH
EPSS
0.0%
2026 CWE-862 1 PoC

Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the ‘Permissions’ field of the JSON response, an attacker could escalate privileges and gain full administrative access. This vulnerability allows all restrictions to be bypassed and completely compromises system management.

CVE-2022-4798
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4799
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1055
Kernel General
8.6
HIGH
EPSS
0.0%
2022 CWE-416 2 PoCs

A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5

CVE-2022-21801
Software Genérico General
8.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to a reboot. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-50909
Algo 8028 General
8.6
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

CVE-2022-33719
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

CVE-2022-50922
Audio Conversion Wizard General
8.6
HIGH
EPSS
0.3%
2022 CWE-120 1 PoC

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.

CVE-2022-23923
jailed General
8.6
HIGH
EPSS
0.1%
2022 2 PoCs

All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.