402 vulnerabilidades · 🔥 KEV · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-44228
🔥 KEV Apache Log4j2 Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-502 276 PoCs

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnera

CVE-2025-10035
🔥 KEV GoAnywhere MFT General ⚡ nuclei
10.0
CRITICAL
EPSS
55.2%
2025 CWE-77 4 PoCs

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVE-2025-32432
🔥 KEV cms Web ⚡ nuclei
10.0
CRITICAL
EPSS
92.6%
2025 CWE-94 6 PoCs

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

CVE-2025-24813
🔥 KEV Apache Tomcat Web ⚡ nuclei
10.0
CRITICAL
EPSS
94.1%
2025 CWE-44 52 PoCs

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive

CVE-2025-55182
🔥 KEV react-server-dom-webpack Web ⚡ nuclei
10.0
CRITICAL
EPSS
82.0%
2025 3 PoCs

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVE-2025-47812
🔥 KEV Wing FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
92.8%
2025 CWE-158 14 PoCs

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

CVE-2025-20281
🔥 KEV Cisco Identity Services Engine Software Web Networking ⚡ nuclei
10.0
CRITICAL
EPSS
36.0%
2025 CWE-74 4 PoCs

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVE-2025-57819
🔥 KEV endpoint General ⚡ nuclei
10.0
CRITICAL
EPSS
76.7%
2025 CWE-89 12 PoCs

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CVE-2025-31324
🔥 KEV SAP NetWeaver (Visual Composer development server) General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2025 CWE-434 20 PoCs

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVE-2020-25213
🔥 KEV Software Genérico Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2020 13 PoCs

The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to write PHP code into the wp-content/plugins/wp-file-manager/lib/files/ directory. This was exploited in the wild in August and September 2020.

CVE-2020-6207
🔥 KEV SAP Solution Manager (User Experience Monitoring) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.2%
2020 6 PoCs

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

CVE-2020-6287
🔥 KEV SAP NetWeaver AS JAVA (LM Configuration Wizard) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2020 8 PoCs

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVE-2022-22947
🔥 KEV Spring Cloud Gateway Web Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.5%
2022 CWE-94 76 PoCs

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

CVE-2022-27593
🔥 KEV Photo Station General ⚡ nuclei
10.0
CRITICAL
EPSS
93.1%
2022 CWE-610 0 PoCs

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-24816
🔥 KEV jai-ext Web ⚡ nuclei
10.0
CRITICAL
EPSS
93.7%
2022 CWE-94 1 PoC

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

CVE-2024-9463
🔥 KEV Expedition Web Networking ⚡ nuclei
9.9
CRITICAL
EPSS
94.2%
2024 CWE-78 2 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVE-2019-10758
🔥 KEV mongo-express General ⚡ nuclei
9.9
CRITICAL
EPSS
94.4%
2019 4 PoCs

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

CVE-2019-11510
🔥 KEV Software Genérico General ⚡ nuclei
9.9
CRITICAL
EPSS
94.5%
2019 12 PoCs

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVE-2025-24016
🔥 KEV wazuh Web ⚡ nuclei
9.9
CRITICAL
EPSS
93.5%
2025 CWE-502 8 PoCs

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anyb

CVE-2025-49113
🔥 KEV Webmail Web ⚡ nuclei
9.9
CRITICAL
EPSS
90.4%
2025 CWE-502 25 PoCs

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.