438 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2014-6271
🔥 KEV Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2014 74 PoCs

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to

CVE-2025-59287
🔥 KEV Windows Server 2012 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
72.2%
2025 CWE-502 4 PoCs

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVE-2020-8644
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2020 3 PoCs

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

CVE-2022-35405
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2022 3 PoCs

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CVE-2020-5135
🔥 KEV SonicOS Networking
9.8
CRITICAL
EPSS
23.8%
2020 CWE-120 1 PoC

A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.

CVE-2021-21985
🔥 KEV VMware vCenter Server and VMware Cloud Foundation Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 13 PoCs

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVE-2023-25717
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2023 1 PoC

Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

CVE-2024-3272
🔥 KEV DNS-320L Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-798 0 PoCs

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products

CVE-2015-7755
🔥 KEV Software Genérico Networking
9.8
CRITICAL
EPSS
85.2%
2015 3 PoCs

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

CVE-2019-3396
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2019 26 PoCs

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CVE-2013-2251
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2013 7 PoCs

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVE-2022-42948
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
21.8%
2022 2 PoCs

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVE-2022-1388
🔥 KEV BIG-IP Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-306 87 PoCs

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-21587
🔥 KEV Web Applications Desktop Integrator Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 6 PoCs

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-24086
🔥 KEV Magento Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2022 CWE-20 15 PoCs

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVE-2018-19410
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2018 1 PoC

PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).