40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2014-5470
Software Genérico General
9.8
CRITICAL
EPSS
78.1%
2014 1 PoC

Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.

CVE-2023-29802
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

CVE-2024-5452
lightning-ai/pytorch-lightning General
9.8
CRITICAL
EPSS
62.6%
2024 CWE-915 2 PoCs

A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist and contains dunder attributes. When processed, this can be exploited to access other modu

CVE-2025-28399
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2025 1 PoC

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

CVE-2022-44928
Software Genérico General
9.8
CRITICAL
EPSS
15.2%
2022 1 PoC

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVE-2025-46108
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

CVE-2024-45166
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.

CVE-2014-9515
Software Genérico General
9.8
CRITICAL
EPSS
5.4%
2014 1 PoC

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

CVE-2024-3847
Chrome General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2023-24799
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2021-25943
101 General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2024-53442
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.

CVE-2023-30967
com.palantir.meta:orbital-simulator General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVE-2021-38241
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2021 1 PoC

Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

CVE-2019-16674
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2019 2 PoCs

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie is predictable and can lead to admin password compromise when captured on the network.

CVE-2022-2024
gogs/gogs General
9.8
CRITICAL
EPSS
42.3%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

CVE-2022-44001
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

CVE-2022-1440
yarkeev/git-interface General
9.8
CRITICAL
EPSS
8.5%
2022 CWE-78 1 PoC

Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.

CVE-2022-44000
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

CVE-2022-47873
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).