1074 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2019-5786
🔥 KEV Chrome General
6.5
MEDIUM
EPSS
89.4%
2019 1 PoC

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2019-6693
🔥 KEV FortiGate General
6.5
MEDIUM
EPSS
72.2%
2019 3 PoCs

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CVE-2023-36761
🔥 KEV Microsoft Office 2019 General
6.5
MEDIUM
EPSS
5.5%
2023 CWE-20 1 PoC

Microsoft Word Information Disclosure Vulnerability

CVE-2025-20362
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Networking ⚡ nuclei
6.5
MEDIUM
EPSS
44.1%
2025 CWE-862 0 PoCs

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2023-20118
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking
6.5
MEDIUM
EPSS
3.8%
2023 CWE-77 1 PoC

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacke

CVE-2019-5591
🔥 KEV Fortinet FortiOS Networking Windows ⚡ nuclei
6.5
MEDIUM
EPSS
48.4%
2019 0 PoCs

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

CVE-2019-5825
🔥 KEV Chrome Web
6.5
MEDIUM
EPSS
73.7%
2019 2 PoCs

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2020-11652
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
93.7%
2020 9 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

CVE-2020-8195
🔥 KEV Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking
6.5
MEDIUM
EPSS
71.7%
2020 CWE-20 2 PoCs

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

CVE-2020-8193
🔥 KEV Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking ⚡ nuclei
6.5
MEDIUM
EPSS
94.4%
2020 CWE-284 6 PoCs

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

CVE-2020-3153
🔥 KEV Cisco AnyConnect Secure Mobility Client Networking Windows
6.5
MEDIUM
EPSS
25.1%
2020 CWE-427 6 PoCs

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related a

CVE-2016-3351
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
45.4%
2016 1 PoC

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVE-2016-9563
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
58.8%
2016 1 PoC

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

CVE-2022-22948
🔥 KEV VMware vCenter Server and VMware Cloud Foundation Cloud
6.5
MEDIUM
EPSS
26.0%
2022 3 PoCs

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

CVE-2021-25395
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.2%
2021 CWE-362 1 PoC

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVE-2021-25394
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.4%
2021 CWE-416 1 PoC

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVE-2020-13965
🔥 KEV Software Genérico Web
6.3
MEDIUM
EPSS
71.8%
2020 2 PoCs

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.