40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-33242
Wallet General
9.6
CRITICAL
EPSS
5.8%
2023 2 PoCs

Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.

CVE-2024-42466
upKeeper Manager General
9.5
CRITICAL
EPSS
0.4%
2024 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

CVE-2025-24971
DumbDrop General
9.5
CRITICAL
EPSS
10.3%
2025 CWE-78 1 PoC

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the **Apprise Notification** enabled. This issue has been addressed in commit `4ff8469d` and all users are advised to patch. There are no known workarounds for this vulnerability.

CVE-2025-6523
Server General
9.5
CRITICAL
EPSS
0.1%
2025 CWE-1391 1 PoC

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier

CVE-2024-13503
NTC2218, NTC2250, NTC2299 General
9.5
CRITICAL
EPSS
0.5%
2024 CWE-120 1 PoC

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, Remote Code Inclusion. This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The issue is both present on the PowerPC versions of the modem and the ARM versions. A stack buffer buffer overflow in the swdownload binary allows attackers to execute arbitrary code. The parse_INFO function uses an unrestricted `sscanf` to read a string of an

CVE-2024-25124
fiber General
9.4
CRITICAL
EPSS
0.5%
2024 CWE-346 2 PoCs

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Control-Allow-Origin header to a wildcard (`*`) while also having the Access-Control-Allow-Credentials set to true, which goes against recommended security best practices. The impact of this misconfiguration is high as it can lead to unauthorized access to sensitive user data and expose the system to various types of attacks listed in the PortSwig

CVE-2023-2868
🔥 KEV Barracuda Email Security Gateway General
9.4
CRITICAL
EPSS
90.8%
2023 CWE-20 4 PoCs

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through

CVE-2022-3741
chatwoot/chatwoot General
9.4
CRITICAL
EPSS
0.5%
2022 CWE-307 1 PoC

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

CVE-2020-28434
gitblame General
9.4
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

CVE-2019-20695
Software Genérico General
9.4
CRITICAL
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects SRK60 before 2.3.5.106, SRR60 before 2.3.5.106, and SRS60 before 2.3.5.106.

CVE-2020-8479
Central Licensing System General
9.4
CRITICAL
EPSS
0.7%
2020 CWE-91 1 PoC

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 an

CVE-2022-0660
microweber/microweber General ⚡ nuclei
9.4
CRITICAL
EPSS
7.5%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2025-9963
P series (P07, P10, P12, P15) General
9.4
CRITICAL
EPSS
0.0%
2025 CWE-22 2 PoCs

A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the system can also be compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2025-8414
Simplicity SDK General
9.4
CRITICAL
EPSS
0.0%
2025 CWE-20 1 PoC

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability.

CVE-2025-34055
IP camera, DVR, and NVR Devices General
9.4
CRITICAL
EPSS
1.8%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system shell without sanitation allowing attackers to execute commands as the root user.

CVE-2022-0401
yuda-lyu/w-zip General
9.4
CRITICAL
EPSS
0.7%
2022 CWE-22 1 PoC

Path Traversal in NPM w-zip prior to 1.0.12.

CVE-2021-20999
UC20-WL2000-AC (No. 1334950000) General
9.4
CRITICAL
EPSS
0.4%
2021 CWE-668 1 PoC

In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the operation may be stopped.

CVE-2011-10010
QuickShare File Server General
9.4
CRITICAL
EPSS
57.9%
2011 CWE-22 5 PoCs

QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writable" option is enabled (default during account creation), this allows attackers to upload arbitrary files to privileged locations such as system32, enabling remote code execution via MOF injection or executable placement.

CVE-2024-35307
Pandora FMS General
9.4
CRITICAL
EPSS
15.3%
2024 CWE-88 1 PoC

Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.

CVE-2023-23770
MBTS Site Controller General
9.4
CRITICAL
EPSS
0.1%
2023 CWE-259 1 PoC

Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.