40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-53591
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

CVE-2026-24107
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2026 1 PoC

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

CVE-2023-51953
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2025-30113
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contains hardcoded credentials that allow unauthorized access to device settings through ports 9091 and 9092. These credentials, stored in cleartext, can be exploited by an attacker who gains access to the dashcam's network.

CVE-2025-28242
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
11.5%
2025 1 PoC

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

CVE-2026-24101
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2026 1 PoC

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1 is not validated, potentially leading to a command injection vulnerability.

CVE-2021-26084
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 54 PoCs

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

CVE-2019-18935
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
93.6%
2019 14 PoCs

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

CVE-2024-42395
HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2025-39596
Quentn WP General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-1390 1 PoC

Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.

CVE-2025-24172
macOS General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

CVE-2023-23461
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Libpeconv – access violation, before commit b076013 (30/11/2022).

CVE-2025-54462
libbiosig General
9.8
CRITICAL
EPSS
0.3%
2025 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-27224
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be used to write to any filename with any file type at any location on the local server, ultimately allowing execution of arbitrary code.

CVE-2023-0851
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i fir

CVE-2023-29805
Software Genérico General
9.8
CRITICAL
EPSS
12.2%
2023 1 PoC

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

CVE-2015-1187
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
82.9%
2015 2 PoCs

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

CVE-2019-3396
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2019 26 PoCs

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.