40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVE-2025-27651
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-014.

CVE-2023-46485
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

CVE-2021-34569
750-81xx/xxx-xxxFW General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-787 1 PoC

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2023-34152
ImageMagick General
9.8
CRITICAL
EPSS
69.5%
2023 CWE-20 2 PoCs

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVE-2023-42374
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2023 3 PoCs

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.

CVE-2023-29665
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2023 1 PoC

D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.

CVE-2021-23390
total4 General
9.8
CRITICAL
EPSS
1.3%
2021 1 PoC

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2024-23746
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

CVE-2023-30967
com.palantir.meta:orbital-simulator General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVE-2023-31060
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.

CVE-2024-50588
Elefant General
9.8
CRITICAL
EPSS
0.4%
2024 CWE-1393 2 PoCs

An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM").

CVE-2024-10811
Endpoint Manager General
9.8
CRITICAL
EPSS
4.7%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2023-32243
Essential Addons for Elementor General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2023 CWE-287 11 PoCs

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

CVE-2024-48453
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 1 PoC

An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

CVE-2023-41999
Arcserve UDP General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-287 1 PoC

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.

CVE-2024-20017
MT6890, MT7915, MT7916, MT7981, MT7986 General
9.8
CRITICAL
EPSS
68.2%
2024 2 PoCs

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

CVE-2023-37903
vm2 General
9.8
CRITICAL
EPSS
36.1%
2023 CWE-78 1 PoC

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.