40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40711
🔥 KEV Backup and Recovery General ⚡ nuclei
9.8
CRITICAL
EPSS
68.2%
2024 4 PoCs

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CVE-2021-34578
PLC General
9.8
CRITICAL
EPSS
0.3%
2021 CWE-287 1 PoC

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware versions up to FW07.

CVE-2023-23076
Software Genérico General
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

CVE-2025-44896
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

CVE-2023-20864
VMware Aria Operations for Logs (formerly vRealize Log Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVE-2024-44000
LiteSpeed Cache General ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2024 CWE-522 6 PoCs

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

CVE-2025-28405
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

CVE-2023-31729
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.

CVE-2023-32117
Integrate Google Drive General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

CVE-2021-31755
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2021 0 PoCs

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVE-2023-35968
YF325 General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-190 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the gwcfg_cgi_set_manage_post_data functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-49340
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

CVE-2019-10068
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2019 2 PoCs

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

CVE-2025-63217
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

CVE-2025-52688
OmniAccess Stellar Products General
9.8
CRITICAL
EPSS
0.2%
2025 CWE-77 2 PoCs

Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading to the loss of confidentiality, integrity, availability, and full control of the access point.

CVE-2019-5133
Accusoft General
9.8
CRITICAL
EPSS
1.7%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2024-25180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 4 PoCs

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

CVE-2024-8381
Firefox General
9.8
CRITICAL
EPSS
11.6%
2024 1 PoC

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVE-2024-56058
VRPConnector General
9.8
CRITICAL
EPSS
43.8%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1.

CVE-2023-51969
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.