964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2009-0556
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
67.9%
2009 1 PoC

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

CVE-2020-10221
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
91.4%
2020 2 PoCs

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

CVE-2020-9377
🔥 KEV Software Genérico Web
8.8
HIGH
EPSS
76.6%
2020 1 PoC

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2008-0015
🔥 KEV Software Genérico Windows
8.8
HIGH
EPSS
81.6%
2008 2 PoCs

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

CVE-2008-3431
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
5.5%
2008 3 PoCs

The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

CVE-2024-7971
🔥 KEV Chrome General
8.8
HIGH
EPSS
1.0%
2024 CWE-843 2 PoCs

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2020-0688
🔥 KEV Microsoft Exchange Server 2013 Windows
8.8
HIGH
EPSS
94.4%
2020 25 PoCs

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

CVE-2022-22620
🔥 KEV Safari (v and ) General
8.8
HIGH
EPSS
4.0%
2022 2 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVE-2025-14174
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2025 1 PoC

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7965
🔥 KEV Chrome General
8.8
HIGH
EPSS
23.8%
2024 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2026-2441
🔥 KEV Chrome General
8.8
HIGH
EPSS
9.5%
2026 CWE-416 1 PoC

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2017-0144
🔥 KEV Windows SMB Windows
8.8
HIGH
EPSS
94.3%
2017 10 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

CVE-2025-8110
🔥 KEV Gogs Web ⚡ nuclei
8.7
HIGH
EPSS
17.7%
2025 CWE-22 1 PoC

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

CVE-2019-11043
🔥 KEV PHP Web
8.7
HIGH
EPSS
94.1%
2019 CWE-120 25 PoCs

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVE-2025-14847
🔥 KEV MongoDB Server Database
8.7
HIGH
EPSS
76.7%
2025 CWE-130 3 PoCs

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater th

CVE-2025-4008
🔥 KEV MeteoBridge General ⚡ nuclei
8.7
HIGH
EPSS
43.9%
2025 CWE-77 1 PoC

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.

CVE-2024-3393
🔥 KEV Cloud NGFW Networking Cloud
8.7
HIGH
EPSS
77.7%
2024 CWE-754 2 PoCs

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVE-2020-3569
🔥 KEV Cisco IOS XR Software Networking
8.6
HIGH
EPSS
4.7%
2020 CWE-400 1 PoC

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. A successful exploit could