40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2014-8361
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.0%
2014 2 PoCs

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVE-2024-36445
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

CVE-2021-42237
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 4 PoCs

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CVE-2017-7921
🔥 KEV Hikvision Cameras General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2017 CWE-287 15 PoCs

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequa

CVE-2021-42777
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2021 2 PoCs

Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.

CVE-2014-5470
Software Genérico General
9.8
CRITICAL
EPSS
78.1%
2014 1 PoC

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.

CVE-2024-36389
DeviceHub General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-330 1 PoC

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

CVE-2024-48359
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

CVE-2022-45717
Software Genérico General
9.8
CRITICAL
EPSS
5.3%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.

CVE-2025-5099
PrinterShare Mobile Print General
9.8
CRITICAL
EPSS
1.0%
2025 CWE-119 1 PoC

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

CVE-2024-25169
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

CVE-2014-9515
Software Genérico General
9.8
CRITICAL
EPSS
5.4%
2014 1 PoC

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

CVE-2025-27681
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004.

CVE-2019-16920
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2019 4 PoCs

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CVE-2025-69929
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

CVE-2021-34569
750-81xx/xxx-xxxFW General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-787 1 PoC

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2021-21947
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-122 1 PoC

Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer overflow takes place when the `SOF3` precision is greater or equal than 9.

CVE-2021-23803
latte/latte General
9.8
CRITICAL
EPSS
0.4%
2021 1 PoC

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

CVE-2024-36858
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
73.6%
2024 0 PoCs

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2022-34668
NVIDIA FLARE General
9.8
CRITICAL
EPSS
22.4%
2022 CWE-502 1 PoC

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.