40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-41940
🔥 KEV cPanel General ⚡ nuclei
9.3
CRITICAL
EPSS
67.0%
2026 CWE-306 1 PoC

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE-2026-41922
WDR201A WiFi Extender General
9.3
CRITICAL
EPSS
1.1%
2026 CWE-78 2 PoCs

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allow unauthenticated remote attackers to execute arbitrary shell commands by injecting malicious input into the sz11gChannel or PIN POST parameters. Attackers can exploit unsanitized parameter handling in the set_wifi_basic and set_wifi_do_wps functions to achieve remote code execution without authentication.

CVE-2026-27476
RustFly General
9.3
CRITICAL
EPSS
0.4%
2026 CWE-78 1 PoC

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.

CVE-2026-26220
LightLLM General
9.3
CRITICAL
EPSS
0.9%
2026 CWE-502 2 PoCs

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD master node exposes WebSocket endpoints that receive binary frames and pass the data directly to pickle.loads() without authentication or validation. A remote attacker who can reach the PD master can send a crafted payload to achieve arbitrary code execution.

CVE-2026-24811
root General
9.3
CRITICAL
EPSS
0.1%
2026 1 PoC

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

CVE-2026-27180
MajorDoMo General
9.3
CRITICAL
EPSS
48.8%
2026 CWE-494 1 PoC

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method through the /objects/?module=saverestore endpoint without authentication because it uses gr('mode') (which reads directly from $_REQUEST) instead of the framework's $this->mode. An attacker can poison the system update URL via the auto_update_settings mode handler, then trigger the force_update handler to initiate the update chain. The autoUpdateSystem() method fetches an Atom feed from the attac

CVE-2026-39987
🔥 KEV marimo General
9.3
CRITICAL
EPSS
78.7%
2026 CWE-306 1 PoC

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

CVE-2026-24812
root General
9.3
CRITICAL
EPSS
0.1%
2026 1 PoC

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1.

CVE-2026-26341
Smart+ General
9.3
CRITICAL
EPSS
0.2%
2026 CWE-1392 1 PoC

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.

CVE-2026-26369
eNet SMART HOME server General
9.3
CRITICAL
EPSS
0.0%
2026 CWE-269 1 PoC

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.

CVE-2026-40042
Pachno General
9.3
CRITICAL
EPSS
0.1%
2026 CWE-403 1 PoC

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_NONET restrictions.

CVE-2026-4181
DIR-816 General
9.3
CRITICAL
EPSS
0.3%
2026 CWE-121 1 PoC

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-53950
WYSIWYG Editor General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVE-2023-53948
Lilac-Reloaded General
9.3
CRITICAL
EPSS
0.5%
2023 CWE-78 1 PoC

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.

CVE-2023-6569
h2oai/h2o-3 General
9.3
CRITICAL
EPSS
0.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in h2oai/h2o-3

CVE-2023-31191
ds230 General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-223 1 PoC

DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages which force the DroneScout ds230 Remote ID receiver to drop real Remote ID (RID) information and, instead, generate and transmit JSON encoded MQTT messages containing crafted RID information. Consequently, the MQTT broker, typically operated by a system integrator, will have no access to the drones’ real RID information.

CVE-2023-53771
MiniDVBLinux Change Root Password PoC General
9.3
CRITICAL
EPSS
1.1%
2023 CWE-306 2 PoCs

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials.

CVE-2023-53951
ever gauzy General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-347 1 PoC

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

CVE-2023-53983
Anevia Flamingo XL/XS General
9.3
CRITICAL
EPSS
0.7%
2023 CWE-798 1 PoC

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

CVE-2023-54329
Inbit Messenger General
9.3
CRITICAL
EPSS
0.6%
2023 CWE-121 1 PoC

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.