402 vulnerabilidades · 🔥 KEV · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-29059
🔥 KEV Microsoft .NET Framework 4.8 General ⚡ nuclei
7.5
HIGH
EPSS
93.7%
2024 CWE-209 0 PoCs

.NET Framework Information Disclosure Vulnerability

CVE-2015-3035
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2015 2 PoCs

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CVE-2019-9621
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2019 4 PoCs

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

CVE-2024-20767
🔥 KEV ColdFusion General ⚡ nuclei
7.4
HIGH
EPSS
94.0%
2024 CWE-284 6 PoCs

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

CVE-2017-3506
🔥 KEV WebLogic Server Web Database ⚡ nuclei
7.4
HIGH
EPSS
94.4%
2017 3 PoCs

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLog

CVE-2024-3273
🔥 KEV DNS-320L Web ⚡ nuclei
7.3
HIGH
EPSS
94.4%
2024 CWE-77 10 PoCs

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE:

CVE-2024-27199
🔥 KEV TeamCity General ⚡ nuclei
7.3
HIGH
EPSS
91.4%
2024 CWE-23 1 PoC

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVE-2021-33766
🔥 KEV Microsoft Exchange Server 2019 Cumulative Update 9 Windows ⚡ nuclei
7.3
HIGH
EPSS
93.6%
2021 2 PoCs

Microsoft Exchange Server Information Disclosure Vulnerability

CVE-2019-2616
🔥 KEV BI Publisher (formerly XML Publisher) Web Database ⚡ nuclei
7.2
HIGH
EPSS
94.0%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI

CVE-2019-0193
🔥 KEV Apache Solr Web ⚡ nuclei
7.2
HIGH
EPSS
93.1%
2019 3 PoCs

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

CVE-2020-14883
🔥 KEV WebLogic Server Web Database ⚡ nuclei
7.2
HIGH
EPSS
94.4%
2020 7 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-0669
🔥 KEV Goanywhere MFT General ⚡ nuclei
7.2
HIGH
EPSS
94.4%
2023 CWE-502 10 PoCs

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

CVE-2021-21311
🔥 KEV adminer Web ⚡ nuclei
7.2
HIGH
EPSS
94.2%
2021 CWE-918 2 PoCs

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9.

CVE-2021-21315
🔥 KEV systeminformation General ⚡ nuclei
7.1
HIGH
EPSS
94.0%
2021 CWE-78 6 PoCs

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

CVE-2025-14611
🔥 KEV CentreStack and TrioFox General ⚡ nuclei
7.1
HIGH
EPSS
58.3%
2025 1 PoC

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

CVE-2024-9474
🔥 KEV Cloud NGFW Networking Cloud ⚡ nuclei
6.9
MEDIUM
EPSS
94.2%
2024 CWE-78 7 PoCs

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-12987
🔥 KEV Vigor2960 General ⚡ nuclei
6.9
MEDIUM
EPSS
79.0%
2024 CWE-78 0 PoCs

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2021-22175
🔥 KEV GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
69.7%
2021 1 PoC

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVE-2025-20362
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Networking ⚡ nuclei
6.5
MEDIUM
EPSS
44.1%
2025 CWE-862 0 PoCs

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc

CVE-2025-49706
🔥 KEV Microsoft SharePoint Enterprise Server 2016 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
75.0%
2025 CWE-287 1 PoC

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.