40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-34102
🔥 KEV Adobe Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-611 29 PoCs

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVE-2026-24109
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this value is used in `sprintf` without validating variable sizes, it could lead to a buffer overflow vulnerability.

CVE-2023-46980
Software Genérico General
9.8
CRITICAL
EPSS
7.5%
2023 3 PoCs

An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

CVE-2023-7227
NVR 504 General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-77 1 PoC

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.

CVE-2024-50485
Exam Matrix General
9.8
CRITICAL
EPSS
21.9%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.

CVE-2024-38438
DSL-225 General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-294 1 PoC

D-Link - CWE-294: Authentication Bypass by Capture-replay

CVE-2023-37214
ERO1xS-Pro Dual-Band WiFi General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

CVE-2024-28515
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

CVE-2023-40890
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVE-2023-29732
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.

CVE-2024-57604
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

CVE-2024-27172
Toshiba Tec e-Studio multi-function peripheral (MFP) General
9.8
CRITICAL
EPSS
30.6%
2024 CWE-78 1 PoC

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

CVE-2024-27764
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

CVE-2023-25367
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

CVE-2023-52031
Software Genérico General
9.8
CRITICAL
EPSS
14.8%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.

CVE-2023-25178
C300 General
9.8
CRITICAL
EPSS
1.3%
2023 CWE-345 1 PoC

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2026-29859
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2023-34566
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

CVE-2023-52027
Software Genérico General
9.8
CRITICAL
EPSS
15.5%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.

CVE-2026-26720
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2026 2 PoCs

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.