40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2017-11357
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
93.7%
2017 2 PoCs

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVE-2021-21938
ImageGear General
9.8
CRITICAL
EPSS
0.8%
2021 CWE-193 1 PoC

A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-24265
macOS General
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVE-2021-30351
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
9.8
CRITICAL
EPSS
0.4%
2021 1 PoC

An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2025-2746
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
89.7%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

CVE-2023-29746
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

CVE-2022-44806
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

CVE-2025-27007
OttoKit General ⚡ nuclei
9.8
CRITICAL
EPSS
81.5%
2025 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

CVE-2014-8361
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.0%
2014 2 PoCs

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVE-2024-23746
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

CVE-2014-5470
Software Genérico General
9.8
CRITICAL
EPSS
78.1%
2014 1 PoC

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.

CVE-2019-10068
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2019 2 PoCs

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

CVE-2022-41220
Software Genérico General
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

CVE-2025-0074
Android General
9.8
CRITICAL
EPSS
1.8%
2025 1 PoC

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2021-1933
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

CVE-2014-9515
Software Genérico General
9.8
CRITICAL
EPSS
5.4%
2014 1 PoC

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

CVE-2019-9201
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2019 1 PoC

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

CVE-2024-23740
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2024 2 PoCs

An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-25153
FileCatalyst General
9.8
CRITICAL
EPSS
82.2%
2024 CWE-472 3 PoCs

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.