286 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2024-22144
Anti-Malware Security and Brute-Force Firewall Networking
9.0
CRITICAL
EPSS
0.7%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

CVE-2024-29385
Software Genérico Networking
9.0
CRITICAL
EPSS
6.6%
2024 1 PoC

DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

CVE-2025-47154
Ladybird Networking
9.0
CRITICAL
EPSS
1.1%
2025 CWE-820 1 PoC

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."

CVE-2018-4031
CUJO Web Networking
9.0
CRITICAL
EPSS
0.4%
2018 1 PoC

An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.

CVE-2018-3963
CUJO Networking
9.0
CRITICAL
EPSS
0.8%
2018 1 PoC

An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostname is inserted into the dhcpd.conf file without prior sanitization, allowing for arbitrary execution of system commands. To trigger this vulnerability, an attacker can send a DHCP request message and set up the corresponding static DHCP entry.

CVE-2018-4007
Shimo VPN Networking
9.0
CRITICAL
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug.