40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-13160
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-45275
mbNET.mini General
9.8
CRITICAL
EPSS
3.4%
2024 CWE-798 1 PoC

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

CVE-2024-36445
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

CVE-2023-35002
ImageGear General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-42850
Software Genérico General
9.8
CRITICAL
EPSS
49.8%
2024 1 PoC

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

CVE-2024-50623
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-434 5 PoCs

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

CVE-2024-31849
Connect General ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2024 CWE-22 1 PoC

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

CVE-2024-35527
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file.

CVE-2024-29849
Backup & Replication General
9.8
CRITICAL
EPSS
53.6%
2024 1 PoC

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

CVE-2024-0799
Unified Data Protection General ⚡ nuclei
9.8
CRITICAL
EPSS
37.9%
2024 CWE-287 1 PoC

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

CVE-2026-22891
libbiosig General
9.8
CRITICAL
EPSS
0.2%
2026 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-31116
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

CVE-2019-17444
Artifactory General ⚡ nuclei
9.8
CRITICAL
EPSS
92.5%
2019 CWE-521 2 PoCs

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

CVE-2024-43468
🔥 KEV Microsoft Configuration Manager General
9.8
CRITICAL
EPSS
83.1%
2024 CWE-89 3 PoCs

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVE-2023-43364
Software Genérico General
9.8
CRITICAL
EPSS
29.6%
2023 1 PoC

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

CVE-2023-26999
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

CVE-2023-29736
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

CVE-2019-11581
🔥 KEV Jira Server and Data Center General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2019 3 PoCs

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

CVE-2019-16670
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2019 2 PoCs

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. The Authentication mechanism has no brute-force prevention.