40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-50649
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

CVE-2023-27388
T&D Corporation and ESPEC MIC CORP. data logger products General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

CVE-2023-52028
Software Genérico General
9.8
CRITICAL
EPSS
20.6%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

CVE-2025-27651
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-014.

CVE-2024-28394
Software Genérico General
9.8
CRITICAL
EPSS
2.0%
2024 1 PoC

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

CVE-2024-31705
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2024 2 PoCs

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

CVE-2021-35464
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 4 PoCs

ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does not require authentication, and remote code execution can be triggered by sending a single crafted /ccversion/* request to the server. The vulnerability exists due to the usage of Sun ONE Application Framework (JATO) found in versions of Java 8 or earlier

CVE-2025-46121
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthentic

CVE-2025-43946
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2025 1 PoC

TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

CVE-2025-25940
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2025 1 PoC

VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.

CVE-2025-54489
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability manifests on line 8970 of biosig.c on the current master branch (35a819fa), when the Tag is 63: else if (tag==63) { uint8_t tag2=255, len2=255; count = 0; while ((count<len) && !(FlagInfiniteLength && len2

CVE-2025-57432
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers to manipulate stream settings, including changing video modes and possibly altering device functionality. No credentials or authentication mechanisms are required to interact with the Telnet interface.

CVE-2024-50507
DS.DownloadList General
9.8
CRITICAL
EPSS
22.1%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

CVE-2024-25421
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

CVE-2023-29300
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2023 CWE-502 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2026-30281
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2025-28024
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi

CVE-2025-63206
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.

CVE-2024-25180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 4 PoCs

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

CVE-2023-3346
MITSUBISHI CNC M800V Series M800VW General
9.8
CRITICAL
EPSS
1.4%
2023 CWE-120 1 PoC

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.