40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-35498
TIBCO EBX General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the legitimate password and it will be accepted as valid. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.123 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, and 5.9.14, TIBCO EBX: versions 6.0.0 and 6.0.1, and TIBCO Product and Service Catalog power

CVE-2023-6234
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-787 2 PoCs

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2024-43468
🔥 KEV Microsoft Configuration Manager General
9.8
CRITICAL
EPSS
83.1%
2024 CWE-89 3 PoCs

Microsoft Configuration Manager Remote Code Execution Vulnerability

CVE-2008-2374
Software Genérico General
9.8
CRITICAL
EPSS
6.4%
2008 1 PoC

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVE-2024-38396
Software Genérico General
9.8
CRITICAL
EPSS
10.3%
2024 3 PoCs

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in tmux integration feature (enabled by default), allows an attacker to inject arbitrary code into the terminal, a different vulnerability than CVE-2024-38395.

CVE-2025-46108
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

CVE-2021-21782
Accusoft General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-45911
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.

CVE-2025-22408
Android General
9.8
CRITICAL
EPSS
2.0%
2025 1 PoC

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2021-23449
vm2 General
9.8
CRITICAL
EPSS
2.2%
2021 1 PoC

This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.

CVE-2025-66045
libbiosig General
9.8
CRITICAL
EPSS
0.1%
2025 CWE-121 1 PoC

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 65

CVE-2019-19230
CA Release Automation General
9.8
CRITICAL
EPSS
5.6%
2019 CWE-502 1 PoC

An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

CVE-2010-5330
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
43.6%
2010 1 PoC

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

CVE-2024-52382
Matix Popup Builder General
9.8
CRITICAL
EPSS
17.4%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.

CVE-2020-10987
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2020 1 PoC

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVE-2025-44898
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2025 1 PoC

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

CVE-2024-56431
Software Genérico General
9.8
CRITICAL
EPSS
11.1%
2024 4 PoCs

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVE-2014-8361
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.0%
2014 2 PoCs

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVE-2021-4039
NWA1100-NH firmware General
9.8
CRITICAL
EPSS
62.8%
2021 CWE-78 1 PoC

A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.

CVE-2024-48590
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.