40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-7193
🔥 KEV QNAP NAS devices General
9.8
CRITICAL
EPSS
25.8%
2019 1 PoC

This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

CVE-2024-45488
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
86.9%
2024 0 PoCs

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

CVE-2023-51717
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

CVE-2023-34048
🔥 KEV VMware vCenter Server General ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2023 1 PoC

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

CVE-2023-25770
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-502 1 PoC

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-52028
Software Genérico General
9.8
CRITICAL
EPSS
20.6%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

CVE-2024-42395
HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2019-9104
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

CVE-2024-43468
🔥 KEV Microsoft Configuration Manager General
9.8
CRITICAL
EPSS
83.1%
2024 CWE-89 3 PoCs

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVE-2024-23917
TeamCity General ⚡ nuclei
9.8
CRITICAL
EPSS
72.9%
2024 CWE-288 0 PoCs

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

CVE-2023-42374
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2023 3 PoCs

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.

CVE-2024-4358
🔥 KEV Telerik Report Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-290 7 PoCs

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

CVE-2026-32746
inetutils General
9.8
CRITICAL
EPSS
4.5%
2026 CWE-120 1 PoC

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

CVE-2023-20520
1st Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

CVE-2023-50643
Software Genérico General
9.8
CRITICAL
EPSS
26.9%
2023 2 PoCs

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVE-2023-25220
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2026-22891
libbiosig General
9.8
CRITICAL
EPSS
0.2%
2026 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-38812
🔥 KEV VMware vCenter Server General
9.8
CRITICAL
EPSS
77.9%
2024 CWE-122 1 PoC

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CVE-2019-16057
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2019 1 PoC

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.