964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-7593
🔥 KEV vTM General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-287 6 PoCs

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

CVE-2021-39226
🔥 KEV grafana DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2021 CWE-287 0 PoCs

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot wit

CVE-2019-7609
🔥 KEV Kibana Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2019 CWE-94 11 PoCs

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVE-2020-5847
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2020 3 PoCs

Unraid through 6.8.0 allows Remote Code Execution.

CVE-2021-32030
🔥 KEV Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 0 PoCs

The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitiga

CVE-2017-18368
🔥 KEV Software Genérico Networking
9.8
CRITICAL
EPSS
93.6%
2017 3 PoCs

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

CVE-2019-16920
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2019 4 PoCs

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

CVE-2018-7602
🔥 KEV core Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2018 6 PoCs

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

CVE-2025-2746
🔥 KEV Xperience General ⚡ nuclei
9.8
CRITICAL
EPSS
89.7%
2025 CWE-288 2 PoCs

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.

CVE-2013-2251
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2013 7 PoCs

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVE-2024-23113
🔥 KEV FortiSwitchManager Networking
9.8
CRITICAL
EPSS
54.4%
2024 CWE-134 19 PoCs

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2017-6077
🔥 KEV Software Genérico Web
9.8
CRITICAL
EPSS
83.2%
2017 1 PoC

ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

CVE-2024-45195
🔥 KEV Apache OFBiz Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-425 1 PoC

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVE-2024-9680
🔥 KEV Firefox General
9.8
CRITICAL
EPSS
30.8%
2024 1 PoC

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVE-2022-42948
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
21.8%
2022 2 PoCs

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVE-2022-1388
🔥 KEV BIG-IP Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-306 87 PoCs

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-24086
🔥 KEV Magento Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2022 CWE-20 15 PoCs

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVE-2022-21445
🔥 KEV Application Development Framework (ADF) Web Database
9.8
CRITICAL
EPSS
92.0%
2022 4 PoCs

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middlewar

CVE-2018-6789
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
86.4%
2018 7 PoCs

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.