38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2018-3945
Foxit PDF Reader Web
8.0
HIGH
EPSS
0.7%
2018 1 PoC

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability.

CVE-2021-35499
TIBCO Nimbus Web
8.0
HIGH
EPSS
0.4%
2021 1 PoC

The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.4.0 and below.

CVE-2026-24840
dokploy DevOps Web
8.0
HIGH
EPSS
0.1%
2026 CWE-798 1 PoC

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dokploy installations use the same database credentials and could be compromised. Version 0.26.6 contains a patch for the issue.

CVE-2024-4835
GitLab DevOps Web
8.0
HIGH
EPSS
7.5%
2024 CWE-79 1 PoC

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVE-2024-52289
authentik Web
7.9
HIGH
EPSS
0.4%
2024 CWE-185 3 PoCs

authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect URI, without escaping characters that have a special meaning in RegEx. Similarly, the documentation did not take this into consideration either. Given a provider with the Redirect URIs set to https://foo.example.com, an attacker can register a domain fooaexample.com, and it will correctly pass validation. authentik 2024.8.

CVE-2023-2827
SAP Plant Connectivity Web
7.9
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests to PCo or the Production Connector, which could have an impact on the integrity of the integration with SAP Digital Manufacturing.

CVE-2025-32355
Software Genérico Web ⚡ nuclei
7.9
HIGH
EPSS
2.0%
2025 1 PoC

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

CVE-2024-24105
Software Genérico Web Database
7.8
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

CVE-2020-8177
https://github.com/curl/curl Web
7.8
HIGH
EPSS
0.0%
2020 CWE-99 2 PoCs

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVE-2024-0091
GPU display driver, vGPU software, and Cloud Gaming Web Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-822 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVE-2024-24092
Software Genérico Web Database
7.8
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

CVE-2024-22369
Apache Camel Web Database
7.8
HIGH
EPSS
4.8%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

CVE-2024-23762
Software Genérico Web
7.8
HIGH
EPSS
0.0%
2024 1 PoC

Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

CVE-2024-23140
AutoCAD Web
7.8
HIGH
EPSS
0.5%
2024 CWE-125 1 PoC

A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVE-2024-22029
Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 DevOps Web
7.8
HIGH
EPSS
0.0%
2024 CWE-732 1 PoC

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVE-2025-2265
Sante PACS Server Web Database
7.8
HIGH
EPSS
0.1%
2025 CWE-916 1 PoC

The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte

CVE-2022-20775
🔥 KEV Cisco Catalyst SD-WAN Web Networking Cloud
7.8
HIGH
EPSS
0.4%
2022 CWE-25 1 PoC

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/cen

CVE-2024-50126
Linux Web Networking
7.8
HIGH
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net: sched: use RCU read-side critical section in taprio_dump() Fix possible use-after-free in 'taprio_dump()' by adding RCU read-side critical section there. Never seen on x86 but found on a KASAN-enabled arm64 system when investigating https://syzkaller.appspot.com/bug?extid=b65e0af58423fc8a73aa: [T15862] BUG: KASAN: slab-use-after-free in taprio_dump+0xa0c/0xbb0 [T15862] Read of size 4 at addr ffff0000d4bb88f8 by task repro/15862 [T15862] [T15862] CPU: 0 UID: 0 PID: 15862 Comm: repro Not tainted 6.11.0-rc1-00293-gdefaf1a

CVE-2025-50505
Software Genérico Web
7.8
HIGH
EPSS
0.0%
2025 1 PoC

Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution, resulting in local privilege escalation.

CVE-2022-41057
Windows 10 Version 1809 Web Windows
7.8
HIGH
EPSS
1.1%
2022 2 PoCs

Windows HTTP.sys Elevation of Privilege Vulnerability