40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-54363
Wp NssUser Register General
9.8
CRITICAL
EPSS
38.2%
2024 CWE-266 2 PoCs

Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

CVE-2023-51959
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

CVE-2023-24762
Software Genérico General
9.8
CRITICAL
EPSS
5.5%
2023 2 PoCs

OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

CVE-2026-32746
inetutils General
9.8
CRITICAL
EPSS
4.5%
2026 CWE-120 1 PoC

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

CVE-2023-6928
ETL3100 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

CVE-2024-33898
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.

CVE-2023-27718
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2023 1 PoC

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-51967
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.

CVE-2026-31151
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.

CVE-2023-43364
Software Genérico General
9.8
CRITICAL
EPSS
29.6%
2023 1 PoC

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

CVE-2024-46451
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

CVE-2026-24109
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability.

CVE-2023-32225
Sysaid General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

CVE-2023-46665
PolyEco1000 General
9.8
CRITICAL
EPSS
0.0%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

CVE-2023-50643
Software Genérico General
9.8
CRITICAL
EPSS
26.9%
2023 2 PoCs

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVE-2023-27396
Multiple OMRON products which implement FINS protocol General
9.8
CRITICAL
EPSS
1.7%
2023 2 PoCs

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versio

CVE-2024-22632
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.

CVE-2023-20520
1st Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

CVE-2023-33669
Software Genérico General
9.8
CRITICAL
EPSS
30.9%
2023 1 PoC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.

CVE-2026-26720
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2026 2 PoCs

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.