40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-5443
DICOM Server General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

CVE-2024-24402
Software Genérico General
9.8
CRITICAL
EPSS
21.5%
2024 1 PoC

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

CVE-2023-42495
Dasan Networks General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-78 1 PoC

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2021-21833
Accusoft General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-119 1 PoC

An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-1920
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2023-38203
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2023 CWE-502 1 PoC

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2026-30283
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2023-27168
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

CVE-2024-25291
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2024 2 PoCs

Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

CVE-2023-0852
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF

CVE-2024-34313
Software Genérico General
9.8
CRITICAL
EPSS
24.7%
2024 1 PoC

An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

CVE-2024-22852
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVE-2026-21413
LibRaw General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-129 2 PoCs

A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-27650
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

CVE-2024-33215
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

CVE-2019-9104
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

CVE-2023-23462
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-190 1 PoC

Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

CVE-2023-29861
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.

CVE-2024-22632
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.