964 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2019-1653
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2019 CWE-284 17 PoCs

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

CVE-2019-19356
🔥 KEV Software Genérico Networking
7.5
HIGH
EPSS
91.1%
2019 3 PoCs

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CVE-2025-11371
🔥 KEV CentreStack and TrioFox General ⚡ nuclei
7.5
HIGH
EPSS
70.1%
2025 4 PoCs

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560

CVE-2023-29552
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
91.9%
2023 1 PoC

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVE-2025-30397
🔥 KEV Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
20.7%
2025 CWE-843 4 PoCs

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVE-2025-54313
🔥 KEV eslint-config-prettier Windows
7.5
HIGH
EPSS
11.6%
2025 CWE-506 3 PoCs

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVE-2023-27532
🔥 KEV Veeam Backup & Replication General
7.5
HIGH
EPSS
82.3%
2023 CWE-306 3 PoCs

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE-2019-1367
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
90.7%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CVE-2019-1429
🔥 KEV Internet Explorer 9 General
7.5
HIGH
EPSS
83.0%
2019 1 PoC

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

CVE-2020-14864
🔥 KEV Business Intelligence Enterprise Edition Web Database ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2020 2 PoCs

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts)

CVE-2020-11738
🔥 KEV Software Genérico Web Windows ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2020 3 PoCs

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

CVE-2019-13608
🔥 KEV Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
71.3%
2019 0 PoCs

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVE-2019-17558
🔥 KEV Apache Solr Web ⚡ nuclei
7.5
HIGH
EPSS
94.5%
2019 6 PoCs

Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource

CVE-2023-21839
🔥 KEV WebLogic Server Database
7.5
HIGH
EPSS
94.1%
2023 10 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-5418
🔥 KEV https://github.com/rails/rails Web ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2019 CWE-22 10 PoCs

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

CVE-2020-0674
🔥 KEV Internet Explorer 10 General
7.5
HIGH
EPSS
93.8%
2020 10 PoCs

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVE-2023-29298
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CVE-2021-20123
🔥 KEV Draytek VigorConnect General ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2021 1 PoC

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CVE-2020-25078
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2020 3 PoCs

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.