40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-24178
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.2%
2025 3 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to break out of its sandbox.

CVE-2025-46120
Software Genérico General
9.8
CRITICAL
EPSS
2.5%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

CVE-2025-4632
🔥 KEV MagicINFO 9 Server General ⚡ nuclei
9.8
CRITICAL
EPSS
49.2%
2025 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

CVE-2021-33990
Software Genérico General
9.8
CRITICAL
EPSS
66.4%
2021 1 PoC

Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.

CVE-2021-23639
md-to-pdf General
9.8
CRITICAL
EPSS
19.9%
2021 2 PoCs

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

CVE-2023-25280
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.1%
2023 1 PoC

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVE-2025-28406
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

CVE-2025-26399
🔥 KEV Web Help Desk General
9.8
CRITICAL
EPSS
26.6%
2025 CWE-502 2 PoCs

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.

CVE-2023-33735
Software Genérico General
9.8
CRITICAL
EPSS
53.2%
2023 1 PoC

D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.

CVE-2025-52095
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll

CVE-2025-26074
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2025 1 PoC

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

CVE-2024-27764
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

CVE-2017-13038
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2017 1 PoC

The PPP parser in tcpdump before 4.9.2 has a buffer over-read in print-ppp.c:handle_mlppp().

CVE-2025-24190
iOS and iPadOS General
9.8
CRITICAL
EPSS
0.2%
2025 4 PoCs

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.

CVE-2025-67113
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into the firmware upgrade pipeline.

CVE-2023-36281
Software Genérico General
9.8
CRITICAL
EPSS
62.2%
2023 3 PoCs

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

CVE-2023-29739
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

CVE-2024-48453
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 1 PoC

An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

CVE-2023-32227
SYnergy Fingerprint Terminals General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-798 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials

CVE-2025-24167
Safari General
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated.