40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-41611
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVE-2024-50483
Meetup General
9.8
CRITICAL
EPSS
54.0%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

CVE-2025-25595
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a brute force attack.

CVE-2025-28402
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

CVE-2023-46685
WBR-6013 General
9.8
CRITICAL
EPSS
0.6%
2023 CWE-259 2 PoCs

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

CVE-2025-63213
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2025 1 PoC

The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker can exploit this vulnerability by sending a specially crafted GET request with a malicious parameter to inject arbitrary commands. These commands are executed with root privileges, allowing attackers to gain full control over the device. This poses a significant security risk to any device running this software.

CVE-2021-21833
Accusoft General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-119 1 PoC

An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-3918
kriszyp/json-schema General
9.8
CRITICAL
EPSS
1.3%
2021 CWE-1321 1 PoC

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2024-45252
Halo version 11.7.1.5 General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-78 1 PoC

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2023-5074
D-View 8 General ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2023 CWE-798 2 PoCs

Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

CVE-2026-27848
MR9600 General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-78 1 PoC

Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

CVE-2021-1965
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
9.8
CRITICAL
EPSS
27.5%
2021 4 PoCs

Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2023-35002
ImageGear General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-36380
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2021 1 PoC

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

CVE-2023-30967
com.palantir.meta:orbital-simulator General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVE-2024-23741
Software Genérico General
9.8
CRITICAL
EPSS
24.2%
2024 2 PoCs

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2026-26832
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2026 1 PoC

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper sanitization

CVE-2024-28986
🔥 KEV Web Help Desk General ⚡ nuclei
9.8
CRITICAL
EPSS
79.7%
2024 CWE-502 0 PoCs

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

CVE-2024-57595
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

CVE-2021-25914
object-collider General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.