1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2025-3248
🔥 KEV langflow Web ⚡ nuclei
9.8
CRITICAL
EPSS
91.8%
2025 CWE-306 22 PoCs

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

CVE-2023-38035
🔥 KEV MobileIron Sentry Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 4 PoCs

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

CVE-2020-15505
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 2 PoCs

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2021-33045
🔥 KEV Some Dahua IP Camera, Video Intercom, NVR, XVR devices General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 3 PoCs

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVE-2023-34048
🔥 KEV VMware vCenter Server General ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2023 1 PoC

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

CVE-2021-31755
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2021 0 PoCs

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.

CVE-2021-44515
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 0 PoCs

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

CVE-2024-50623
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-434 5 PoCs

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

CVE-2020-11651
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.2%
2020 14 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVE-2024-4577
🔥 KEV PHP Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-78 85 PoCs

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVE-2024-34102
🔥 KEV Adobe Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-611 29 PoCs

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVE-2013-4810
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
89.7%
2013 1 PoC

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

CVE-2021-42258
🔥 KEV Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2021 1 PoC

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.

CVE-2019-3929
🔥 KEV Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4. Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2019 CWE-79 5 PoCs

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVE-2014-1776
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
84.0%
2014 2 PoCs

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."

CVE-2015-1187
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
82.9%
2015 2 PoCs

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

CVE-2014-6287
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2014 17 PoCs

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.