40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-40394
Gerbv General
10.0
CRITICAL
EPSS
0.6%
2021 1 PoC

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2014-0787
KingSCADA General
10.0
UNKNOWN
EPSS
50.9%
2014 CWE-121 1 PoC

Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet.

CVE-2024-51378
🔥 KEV Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 5 PoCs

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2023-40151
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-749 1 PoC

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2021-43936
WebHMI General
10.0
CRITICAL
EPSS
28.4%
2021 2 PoCs

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

CVE-2014-125124
Pandora FMS General
10.0
CRITICAL
EPSS
36.0%
2014 CWE-78 2 PoCs

An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing arbitrary command execution as the pandora user. In certain versions (notably 4.1 and 5.0RC1), the pandora user can elevate privileges to root without a password using a chain involving the artica user account. This account is typically installed without a password and is configured to

CVE-2023-5572
vriteio/vrite General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2023-4804
Quantum HD Unity Compressor General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-489 1 PoC

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

CVE-2023-7163
D-View 8 General
10.0
CRITICAL
EPSS
3.4%
2023 CWE-20 1 PoC

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory becoming full, or the execution of tasks on other probes.

CVE-2023-6977
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
83.0%
2023 CWE-29 1 PoC

This vulnerability enables malicious users to read sensitive files on the server.

CVE-2023-2356
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
90.5%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

CVE-2023-42770
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.2%
2023 CWE-288 1 PoC

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2021-40419
Software Genérico General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-489 1 PoC

A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2017-14468
Allen Bradley General
10.0
CRITICAL
EPSS
42.6%
2017 1 PoC

An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE or PROG Description: This ability is leveraged in a larger exploit to flash custom firmware.

CVE-2017-2853
Natus General
10.0
CRITICAL
EPSS
1.8%
2017 1 PoC

An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-41269
cron-utils General
10.0
CRITICAL
EPSS
1.9%
2021 CWE-94 1 PoC

cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no kno

CVE-2021-21940
Anker General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-21820
D-Link General
10.0
CRITICAL
EPSS
2.0%
2021 CWE-798 1 PoC

A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-3765
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
91.5%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

CVE-2023-48418
Pixel Watch General
10.0
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation