40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-20760
Software Genérico General
8.3
HIGH
EPSS
0.2%
2019 1 PoC

NETGEAR R9000 devices before 1.0.4.26 are affected by authentication bypass.

CVE-2024-46436
Software Genérico General
8.3
HIGH
EPSS
1.0%
2024 1 PoC

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

CVE-2025-55903
Software Genérico General
8.3
HIGH
EPSS
0.1%
2025 2 PoCs

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in client-facing documents.

CVE-2023-0227
pyload/pyload General
8.3
HIGH
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.

CVE-2020-27652
DiskStation Manager (DSM) General
8.3
HIGH
EPSS
0.4%
2020 CWE-327 2 PoCs

Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.

CVE-2023-5846
TS-550 General
8.3
HIGH
EPSS
0.0%
2023 CWE-916 1 PoC

Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.

CVE-2023-4815
answerdev/answer General
8.3
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.

CVE-2023-3548
IQ Wifi 6 General
8.3
HIGH
EPSS
0.2%
2023 CWE-307 1 PoC

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

CVE-2017-2797
DMC HTMLFilter General
8.3
HIGH
EPSS
0.3%
2017 1 PoC

An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.

CVE-2022-2732
openemr/openemr General
8.3
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2023-3243
BCM-WEB General
8.3
HIGH
EPSS
0.1%
2023 CWE-290 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVE-2021-26566
Synology DiskStation Manager (DSM) General
8.3
HIGH
EPSS
0.5%
2021 CWE-201 1 PoC

Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.

CVE-2023-40465
ALEOS General
8.3
HIGH
EPSS
0.0%
2023 CWE-121 1 PoC

Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.

CVE-2021-23405
pimcore/pimcore General
8.3
HIGH
EPSS
0.0%
2021 1 PoC

This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.

CVE-2017-2793
DMC HTMLFilter General
8.3
HIGH
EPSS
0.9%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

CVE-2020-6296
SAP NetWeaver (ABAP Server) and ABAP Platform General
8.3
HIGH
EPSS
0.6%
2020 2 PoCs

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

CVE-2023-32226
Sysaid General
8.3
HIGH
EPSS
0.1%
2023 CWE-552 1 PoC

Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecified method.

CVE-2017-2798
DMC HTMLFilter General
8.3
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability.

CVE-2022-1285
gogs/gogs General
8.3
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVE-2025-0291
Chrome General
8.3
HIGH
EPSS
12.1%
2025 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)