438 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2018-1000861
🔥 KEV Software Genérico DevOps ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2018 2 PoCs

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

CVE-2022-22954
🔥 KEV VMware Workspace ONE Access and Identity Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 36 PoCs

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVE-2022-24112
🔥 KEV Apache APISIX Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-290 16 PoCs

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

CVE-2013-2251
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2013 7 PoCs

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVE-2025-32756
🔥 KEV FortiNDR Networking
9.6
CRITICAL
EPSS
41.6%
2025 CWE-121 6 PoCs

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a r

CVE-2024-29824
🔥 KEV EPM Database ⚡ nuclei
9.6
CRITICAL
EPSS
94.0%
2024 3 PoCs

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

CVE-2024-4947
🔥 KEV Chrome General
9.6
CRITICAL
EPSS
0.3%
2024 2 PoCs

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21762
🔥 KEV FortiProxy Networking
9.6
CRITICAL
EPSS
92.7%
2024 CWE-787 27 PoCs

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

CVE-2024-55591
🔥 KEV FortiOS General ⚡ nuclei
9.6
CRITICAL
EPSS
94.1%
2024 CWE-288 11 PoCs

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CVE-2023-41265
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.6
CRITICAL
EPSS
92.4%
2023 1 PoC

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVE-2025-25257
🔥 KEV FortiWeb Web Networking Database ⚡ nuclei
9.6
CRITICAL
EPSS
22.1%
2025 CWE-89 13 PoCs

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVE-2025-54948
🔥 KEV Trend Micro Apex One General
9.4
CRITICAL
EPSS
8.8%
2025 CWE-78 1 PoC

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

CVE-2025-8876
🔥 KEV N-central General
9.4
CRITICAL
EPSS
10.3%
2025 CWE-20 1 PoC

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CVE-2025-8875
🔥 KEV N-central General
9.4
CRITICAL
EPSS
3.0%
2025 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

CVE-2023-4966
🔥 KEV NetScaler ADC Networking Windows ⚡ nuclei
9.4
CRITICAL
EPSS
94.3%
2023 CWE-119 15 PoCs

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CVE-2026-33634
🔥 KEV setup-trivy General
9.4
CRITICAL
EPSS
16.8%
2026 CWE-506 1 PoC

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to ex

CVE-2024-8963
🔥 KEV CSA (Cloud Services Appliance) Cloud ⚡ nuclei
9.4
CRITICAL
EPSS
94.2%
2024 CWE-22 1 PoC

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

CVE-2023-2868
🔥 KEV Barracuda Email Security Gateway General
9.4
CRITICAL
EPSS
90.8%
2023 CWE-20 4 PoCs

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through