964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2017-17562
🔥 KEV Software Genérico Web ⚡ nuclei
8.1
HIGH
EPSS
94.3%
2017 9 PoCs

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

CVE-2024-21412
🔥 KEV Windows 11 version 21H2 Windows
8.1
HIGH
EPSS
93.8%
2024 CWE-693 2 PoCs

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2014-100005
🔥 KEV Software Genérico Web Networking
8.0
HIGH
EPSS
45.9%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

CVE-2025-6204
🔥 KEV DELMIA Apriso General ⚡ nuclei
8.0
HIGH
EPSS
7.2%
2025 CWE-94 0 PoCs

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVE-2019-11539
🔥 KEV Software Genérico General
8.0
HIGH
EPSS
93.9%
2019 5 PoCs

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVE-2020-1380
🔥 KEV Internet Explorer 11 General
7.8
HIGH
EPSS
91.7%
2020 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or de

CVE-2017-0199
🔥 KEV Office/WordPad Web Windows
7.8
HIGH
EPSS
94.3%
2017 24 PoCs

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

CVE-2017-0263
🔥 KEV Microsoft Windows Windows
7.8
HIGH
EPSS
20.3%
2017 3 PoCs

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVE-2014-3153
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
68.9%
2014 6 PoCs

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

CVE-2023-21608
🔥 KEV Acrobat Reader General
7.8
HIGH
EPSS
77.5%
2023 CWE-416 3 PoCs

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2017-11826
🔥 KEV Microsoft Office Windows
7.8
HIGH
EPSS
90.9%
2017 3 PoCs

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

CVE-2017-8291
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
92.9%
2017 4 PoCs

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

CVE-2017-1000253
🔥 KEV Software Genérico Web
7.8
HIGH
EPSS
57.0%
2017 4 PoCs

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ bin

CVE-2026-21509
🔥 KEV Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
12.5%
2026 CWE-807 2 PoCs

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVE-2023-36424
🔥 KEV Windows 11 version 22H3 Windows
7.8
HIGH
EPSS
8.0%
2023 CWE-125 2 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2017-8540
🔥 KEV Malware Protection Engine Windows
7.8
HIGH
EPSS
79.4%
2017 1 PoC

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.

CVE-2017-16651
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
37.3%
2017 3 PoCs

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

CVE-2004-0210
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
6.8%
2004 1 PoC

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

CVE-2019-0841
🔥 KEV Windows Windows
7.8
HIGH
EPSS
82.7%
2019 11 PoCs

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.