40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0851
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i fir

CVE-2024-22988
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.

CVE-2023-46665
PolyEco1000 General
9.8
CRITICAL
EPSS
0.0%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

CVE-2023-51963
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

CVE-2023-46485
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

CVE-2024-45275
mbNET.mini General
9.8
CRITICAL
EPSS
3.4%
2024 CWE-798 1 PoC

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

CVE-2023-29746
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

CVE-2026-24105
Software Genérico General
9.8
CRITICAL
EPSS
2.0%
2026 1 PoC

An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

CVE-2021-4129
Firefox General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 95, Firefox ESR < 91.4.0, and Thunderbird < 91.4.0.

CVE-2024-13804
HPE Insight Cluster Management Utility (CMU) General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

Unauthenticated RCE in HPE Insight Cluster Management Utility

CVE-2024-34102
🔥 KEV Adobe Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-611 29 PoCs

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVE-2023-30013
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2023 1 PoC

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

CVE-2024-46451
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

CVE-2024-25830
Software Genérico General
9.8
CRITICAL
EPSS
39.1%
2024 1 PoC

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

CVE-2026-5443
DICOM Server General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

CVE-2026-30283
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2024-33898
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.

CVE-2023-45498
Software Genérico General
9.8
CRITICAL
EPSS
79.5%
2023 4 PoCs

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

CVE-2024-36389
DeviceHub General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-330 1 PoC

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

CVE-2024-31705
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2024 2 PoCs

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.