964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2025-5419
🔥 KEV Chrome General
8.8
HIGH
EPSS
3.5%
2025 5 PoCs

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2014-0502
🔥 KEV Software Genérico Windows
8.8
HIGH
EPSS
90.6%
2014 1 PoC

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

CVE-2019-0541
🔥 KEV Microsoft Office Windows
8.8
HIGH
EPSS
83.4%
2019 1 PoC

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.

CVE-2012-1889
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
93.1%
2012 2 PoCs

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVE-2024-0519
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2024 2 PoCs

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-38189
🔥 KEV Microsoft Office 2019 General
8.8
HIGH
EPSS
43.7%
2024 CWE-20 1 PoC

Microsoft Project Remote Code Execution Vulnerability

CVE-2019-12991
🔥 KEV Software Genérico Networking
8.8
HIGH
EPSS
80.8%
2019 2 PoCs

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

CVE-2019-15949
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
87.1%
2019 2 PoCs

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.

CVE-2021-21148
🔥 KEV Chrome General
8.8
HIGH
EPSS
24.9%
2021 2 PoCs

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2024-29988
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
60.5%
2024 CWE-693 2 PoCs

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2021-30858
🔥 KEV macOS General
8.8
HIGH
EPSS
0.8%
2021 5 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2013-1690
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
47.1%
2013 1 PoC

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CVE-2021-22894
🔥 KEV Pulse Connect Secure General
8.8
HIGH
EPSS
24.8%
2021 CWE-94 1 PoC

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

CVE-2021-3493
🔥 KEV linux kernel General
8.8
HIGH
EPSS
77.1%
2021 CWE-270 21 PoCs

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

CVE-2021-28663
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
2.7%
2021 3 PoCs

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.

CVE-2017-6884
🔥 KEV Software Genérico Networking
8.8
HIGH
EPSS
90.1%
2017 1 PoC

A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

CVE-2021-30551
🔥 KEV Chrome General
8.8
HIGH
EPSS
78.4%
2021 1 PoC

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2017-0146
🔥 KEV Windows SMB Windows
8.8
HIGH
EPSS
93.3%
2017 5 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.