40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-46685
WBR-6013 General
9.8
CRITICAL
EPSS
0.6%
2023 CWE-259 2 PoCs

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

CVE-2024-39705
Software Genérico General
9.8
CRITICAL
EPSS
10.8%
2024 1 PoC

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

CVE-2023-25220
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2024-1015
E-DDC3.3 General
9.8
CRITICAL
EPSS
3.7%
2024 CWE-94 1 PoC

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

CVE-2026-1358
Airleader Master General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-434 1 PoC

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

CVE-2023-2479
appium/appium-desktop General ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2023 CWE-78 0 PoCs

OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.

CVE-2019-20461
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2019 1 PoC

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. Based upon the reverse engineering, no password or username is ever transferred over this protocol. Thus, one can set up the camera connection feed with only the encoded UID. It is possible to set up sessions with the camera over the Internet by using the encoded UID and the custom UDP protocol, because authentication happens at the client side.

CVE-2024-43468
🔥 KEV Microsoft Configuration Manager General
9.8
CRITICAL
EPSS
83.1%
2024 CWE-89 3 PoCs

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVE-2023-46480
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2023 1 PoC

An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.

CVE-2024-48359
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

CVE-2021-4129
Firefox General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 95, Firefox ESR < 91.4.0, and Thunderbird < 91.4.0.

CVE-2021-23376
ffmpegdotjs General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-21914
ImageGear General
9.8
CRITICAL
EPSS
1.2%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2019-13656
Client Automation General
9.8
CRITICAL
EPSS
14.6%
2019 CWE-284 1 PoC

An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

CVE-2023-34152
ImageMagick General
9.8
CRITICAL
EPSS
69.5%
2023 CWE-20 2 PoCs

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVE-2024-25291
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2024 2 PoCs

Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

CVE-2023-51959
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

CVE-2023-51277
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.

CVE-2023-7017
Kontrol Lux General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

CVE-2024-27172
Toshiba Tec e-Studio multi-function peripheral (MFP) General
9.8
CRITICAL
EPSS
30.6%
2024 CWE-78 1 PoC

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.