40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-30285
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
9.3
CRITICAL
EPSS
0.0%
2021 1 PoC

Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2019-25568
Memu Play General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-306 1 PoC

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

CVE-2025-34516
EVE X1 Server General
9.3
CRITICAL
EPSS
0.2%
2025 CWE-1392 1 PoC

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.

CVE-2018-25316
W General
9.3
CRITICAL
EPSS
0.2%
2018 CWE-290 1 PoC

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS servers and redirect user traffic to malicious sites.

CVE-2024-9129
Zend Server General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-134 1 PoC

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

CVE-2023-54329
Inbit Messenger General
9.3
CRITICAL
EPSS
0.6%
2023 CWE-121 1 PoC

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVE-2019-25614
Free Float FTP General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-787 1 PoC

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

CVE-2012-10055
FTP Server General
9.3
CRITICAL
EPSS
58.9%
2012 CWE-134 4 PoCs

ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically WSACleanup from Ws2_32.dll). This allows the attacker to redirect execution flow and bypass DEP protections using a ROP chain, ultimately leading to arbitrary code execution. The vulnerability is exploitable without authentication and affects default configurations.

CVE-2024-27954
Automatic General ⚡ nuclei
9.3
CRITICAL
EPSS
93.4%
2024 CWE-22 4 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

CVE-2019-25291
Smartliving SmartLAN/G/SI General
9.3
CRITICAL
EPSS
0.1%
2019 CWE-798 2 PoCs

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.

CVE-2021-47891
Unified Remote General
9.3
CRITICAL
EPSS
0.2%
2021 CWE-306 1 PoC

Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and execute malicious payloads.

CVE-2024-0815
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

CVE-2025-2776
🔥 KEV SysAid On-Prem General ⚡ nuclei
9.3
CRITICAL
EPSS
62.6%
2025 CWE-611 2 PoCs

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CVE-2025-34068
WLAN AP WEA453e General
9.3
CRITICAL
EPSS
3.4%
2025 CWE-306 1 PoC

An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.2.4.T1 via improper input validation in the “Tech Support” diagnostic functionality. The command1 and command2 POST or GET parameters accept arbitrary shell commands that are executed with root privileges on the underlying operating system. An attacker can exploit this by crafting a request that injects shell commands to create output files in writable directories and then access their contents via the download endpoint. This flaw allows complete compromise of the device with

CVE-2025-46412
Liebert RDU101 General
9.3
CRITICAL
EPSS
0.3%
2025 CWE-288 1 PoC

Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.

CVE-2025-25038
MiniDVBLinux General
9.3
CRITICAL
EPSS
29.2%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

CVE-2025-53391
zulucrypt General
9.3
CRITICAL
EPSS
0.1%
2025 CWE-863 2 PoCs

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.

CVE-2025-15114
lares General
9.3
CRITICAL
EPSS
0.0%
2025 CWE-403 1 PoC

Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system without additional authentication.

CVE-2018-25220
BOCHS General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-787 1 PoC

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges.

CVE-2025-54574
squid General
9.3
CRITICAL
EPSS
3.9%
2025 CWE-122 1 PoC

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.