40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2017-2877
Foscam C1 Indoor HD Camera General
9.8
CRITICAL
EPSS
0.5%
2017 1 PoC

A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to factory defaults, without authentication.

CVE-2023-37214
ERO1xS-Pro Dual-Band WiFi General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

CVE-2020-13585
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-44353
ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-502 1 PoC

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2021-27651
Pega Infinity General ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2021 CWE-287 5 PoCs

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

CVE-2021-25914
object-collider General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2024-3408
man-group/dtale General ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2024 CWE-798 0 PoCs

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass aut

CVE-2021-25928
safe-obj General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2024-39844
Software Genérico General
9.8
CRITICAL
EPSS
37.1%
2024 1 PoC

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

CVE-2022-44201
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVE-2019-5544
🔥 KEV ESXi and Horizon DaaS General
9.8
CRITICAL
EPSS
92.5%
2019 2 PoCs

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

CVE-2024-54809
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.

CVE-2022-26134
🔥 KEV Confluence Data Center General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 84 PoCs

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-48113
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2022 1 PoC

A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

CVE-2022-46583
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

CVE-2022-46290
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-122 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.The loop that stores the coordinates does not check its index against nAtoms

CVE-2019-5133
Accusoft General
9.8
CRITICAL
EPSS
1.7%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2022-47027
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

CVE-2022-43000
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

CVE-2020-6075
Accusoft General
9.8
CRITICAL
EPSS
1.4%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.