40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-26720
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2026 2 PoCs

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

CVE-2023-34566
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

CVE-2024-0039
Android General
9.8
CRITICAL
EPSS
19.6%
2024 3 PoCs

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-24797
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2023 1 PoC

D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2024-22836
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

CVE-2023-26689
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVE-2024-38812
🔥 KEV VMware vCenter Server General
9.8
CRITICAL
EPSS
77.9%
2024 CWE-122 1 PoC

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CVE-2026-20911
LibRaw General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-131 2 PoCs

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-25078
Experion Server General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-787 1 PoC

Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2024-46455
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVE-2023-32224
DSL-224 firmware version 3.0.10 General
9.8
CRITICAL
EPSS
0.9%
2023 CWE-307 1 PoC

D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

CVE-2024-48126
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

CVE-2024-54805
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.

CVE-2023-29727
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of privilege attack.

CVE-2023-51967
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.

CVE-2026-1358
Airleader Master General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-434 1 PoC

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

CVE-2019-5187
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2019-7193
🔥 KEV QNAP NAS devices General
9.8
CRITICAL
EPSS
25.8%
2019 1 PoC

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.