1074 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2012-0158
🔥 KEV Software Genérico Database
8.8
HIGH
EPSS
94.3%
2012 3 PoCs

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers "system state" corruption, as exploited in

CVE-2021-25298
🔥 KEV Software Genérico Web Cloud ⚡ nuclei
8.8
HIGH
EPSS
75.2%
2021 3 PoCs

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

CVE-2025-10585
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.7%
2025 CWE-843 3 PoCs

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2021-37975
🔥 KEV Chrome General
8.8
HIGH
EPSS
63.0%
2021 2 PoCs

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2025-14174
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2013-2729
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
89.6%
2013 1 PoC

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

CVE-2015-4495
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
71.6%
2015 3 PoCs

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

CVE-2021-21224
🔥 KEV Chrome General
8.8
HIGH
EPSS
46.9%
2021 2 PoCs

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2022-41080
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
93.8%
2022 1 PoC

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-41128
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
39.2%
2022 1 PoC

Windows Scripting Languages Remote Code Execution Vulnerability

CVE-2022-26500
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
19.0%
2022 1 PoC

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

CVE-2023-33538
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
90.6%
2023 2 PoCs

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

CVE-2021-25297
🔥 KEV Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2021 3 PoCs

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

CVE-2019-11043
🔥 KEV PHP Web
8.7
HIGH
EPSS
94.1%
2019 CWE-120 25 PoCs

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVE-2025-14847
🔥 KEV MongoDB Server Database
8.7
HIGH
EPSS
76.7%
2025 CWE-130 3 PoCs

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater th

CVE-2025-4008
🔥 KEV MeteoBridge General ⚡ nuclei
8.7
HIGH
EPSS
43.9%
2025 CWE-77 1 PoC

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

CVE-2024-3393
🔥 KEV Cloud NGFW Networking Cloud
8.7
HIGH
EPSS
77.7%
2024 CWE-754 2 PoCs

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVE-2025-8110
🔥 KEV Gogs Web ⚡ nuclei
8.7
HIGH
EPSS
17.7%
2025 CWE-22 1 PoC

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVE-2024-48248
🔥 KEV Backup & Replication Director Networking ⚡ nuclei
8.6
HIGH
EPSS
94.0%
2024 CWE-36 3 PoCs

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).