40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-27650
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

CVE-2026-1358
Airleader Master General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-434 1 PoC

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

CVE-2019-9096
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords.

CVE-2023-29746
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

CVE-2023-29827
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
82.5%
2023 0 PoCs

ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.

CVE-2023-28507
UniData General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-400 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory-exhaustion issue, where a decompression routine will allocate increasing amounts of memory until all system memory is exhausted and the forked process crashes.

CVE-2023-28504
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2026-30276
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2024-23705
Android General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2023-52027
Software Genérico General
9.8
CRITICAL
EPSS
15.5%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.

CVE-2023-29300
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2023 CWE-502 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2023-42282
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2023 2 PoCs

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CVE-2024-2056
Artica Proxy General
9.8
CRITICAL
EPSS
4.9%
2024 CWE-288 2 PoCs

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed.

CVE-2024-23759
Software Genérico General
9.8
CRITICAL
EPSS
67.1%
2024 1 PoC

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

CVE-2024-10811
Endpoint Manager General
9.8
CRITICAL
EPSS
4.7%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2026-22891
libbiosig General
9.8
CRITICAL
EPSS
0.2%
2026 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-31729
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.

CVE-2024-50476
GRÜN spendino Spendenformular General
9.8
CRITICAL
EPSS
24.7%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.