40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-22521
Benchmark Programming Tool General
7.3
HIGH
EPSS
0.1%
2022 CWE-732 2 PoCs

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

CVE-2021-36287
VNX2 General
7.3
HIGH
EPSS
2.1%
2021 CWE-78 1 PoC

Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.

CVE-2025-20931
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.

CVE-2021-23399
wincred General
7.3
HIGH
EPSS
0.8%
2021 1 PoC

This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-45526
Software Genérico General
7.3
HIGH
EPSS
0.4%
2021 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX6000 before 1.0.0.38, EX6120 before 1.0.0.48, EX6130 before 1.0.0.30, R6300v2 before 1.0.4.52, R6400 before 1.0.1.52, R7000 before 1.0.11.126, R7900 before 1.0.4.30, R8000 before 1.0.4.52, R7000P before 1.3.2.124, R8000P before 1.4.1.50, RAX80 before 1.0.3.88, R6900P before 1.3.2.124, R7900P before 1.4.1.50, and RAX75 before 1.0.3.88.

CVE-2021-4069
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2018-10877
kernel General
7.3
HIGH
EPSS
0.2%
2018 CWE-125 2 PoCs

Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.

CVE-2020-28462
ion-parser General
7.3
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2025-9966
P series (P07, P10, P12, P15) General
7.3
HIGH
EPSS
0.0%
2025 CWE-269 2 PoCs

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2022-1073
Automatic Question Paper Generator General
7.3
HIGH
EPSS
0.3%
2022 CWE-640 1 PoC

A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

CVE-2019-11847
Software Genérico General
7.3
HIGH
EPSS
0.0%
2019 1 PoC

An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.

CVE-2019-14811
ghostscript General
7.3
HIGH
EPSS
1.7%
2019 CWE-648 1 PoC

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CVE-2019-3835
ghostscript General
7.3
HIGH
EPSS
1.6%
2019 CWE-648 2 PoCs

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVE-2019-11288
Pivotal tc Server 4.x General
7.3
HIGH
EPSS
0.1%
2019 CWE-269 1 PoC

In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9.x versions prior to 9.0.27.A, when a tc Runtime instance is configured with the JMX Socket Listener, a local attacker without access to the tc Runtime process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete c

CVE-2019-20679
Software Genérico General
7.3
HIGH
EPSS
0.5%
2019 1 PoC

NETGEAR MR1100 devices before 12.06.08.00 are affected by lack of access control at the function level.

CVE-2022-1795
gpac/gpac General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2022-1061
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-122 1 PoC

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

CVE-2019-3838
ghostscript General
7.3
HIGH
EPSS
1.4%
2019 CWE-648 2 PoCs

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVE-2022-1160
vim/vim General
7.3
HIGH
EPSS
0.6%
2022 CWE-122 1 PoC

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVE-2019-6754
Reader General
7.3
HIGH
EPSS
1.1%
2019 CWE-22 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the localFileStorage method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7407.