40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-30013
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2023 1 PoC

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

CVE-2023-1307
froxlor/froxlor General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

CVE-2021-33353
Software Genérico General
9.8
CRITICAL
EPSS
1.9%
2021 1 PoC

Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.

CVE-2021-46760
3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

CVE-2024-54805
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to achieve command execution.

CVE-2025-66048
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 133

CVE-2023-39453
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

CVE-2023-46685
WBR-6013 General
9.8
CRITICAL
EPSS
0.6%
2023 CWE-259 2 PoCs

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

CVE-2017-6862
🔥 KEV NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42 General
9.8
CRITICAL
EPSS
43.1%
2017 1 PoC

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261.

CVE-2017-2922
Mongoose General
9.8
CRITICAL
EPSS
2.7%
2017 1 PoC

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.

CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVE-2024-24116
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
88.9%
2024 0 PoCs

An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

CVE-2024-23746
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

CVE-2023-25220
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2024-52475
Wawp General
9.8
CRITICAL
EPSS
29.1%
2024 CWE-288 2 PoCs

Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18.

CVE-2025-59359
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2025 CWE-78 1 PoC

The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.

CVE-2017-7921
🔥 KEV Hikvision Cameras General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2017 CWE-287 15 PoCs

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequa

CVE-2024-6890
Journyx (jtime) General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-321 2 PoCs

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

CVE-2024-48126
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.