40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22320
Operational Decision Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2024 CWE-502 1 PoC

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

CVE-2024-23759
Software Genérico General
9.8
CRITICAL
EPSS
67.1%
2024 1 PoC

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

CVE-2025-46060
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2025 1 PoC

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component

CVE-2025-11148
check-branches General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-78 1 PoC

All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted with locally, or via CI, to confirm no conflicts exist in git branches. However, the library follows these conventions which can be abused: 1. It trusts branch names as they are (plain text) 2. It spawns git commands by concatenating user input Since a branch name is potentially a user input - as users can create branches remotely via pull requests, or simply due to privileged access to a repository - it can effectively be abused to run any command.

CVE-2024-23739
Software Genérico General
9.8
CRITICAL
EPSS
35.8%
2024 2 PoCs

An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2023-28489
CP-8031 MASTER MODULE General
9.8
CRITICAL
EPSS
2.7%
2023 CWE-77 2 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

CVE-2023-38389
JupiterX Core General
9.8
CRITICAL
EPSS
11.8%
2023 CWE-863 1 PoC

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

CVE-2018-19323
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
14.7%
2018 4 PoCs

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVE-2024-50478
1-Click Login: Passwordless Authentication General
9.8
CRITICAL
EPSS
28.6%
2024 CWE-305 1 PoC

Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

CVE-2021-1972
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
9.8
CRITICAL
EPSS
0.4%
2021 1 PoC

Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-40506
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in execution.

CVE-2020-13556
EIP Stack Group General
9.8
CRITICAL
EPSS
2.6%
2020 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2013-4810
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
89.7%
2013 1 PoC

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

CVE-2025-47646
PSW Front-end Login & Registration General ⚡ nuclei
9.8
CRITICAL
EPSS
8.9%
2025 CWE-640 2 PoCs

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.

CVE-2025-1009
Firefox General
9.8
CRITICAL
EPSS
0.8%
2025 1 PoC

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.

CVE-2023-28501
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-190 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.

CVE-2025-29165
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

CVE-2025-24231
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVE-2023-26068
Software Genérico General
9.8
CRITICAL
EPSS
81.3%
2023 1 PoC

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).