1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2021-1905
🔥 KEV Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
8.4
HIGH
EPSS
0.6%
2021 1 PoC

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-33739
🔥 KEV Windows 10 Version 1909 Windows
8.4
HIGH
EPSS
19.0%
2021 2 PoCs

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-1708
🔥 KEV ScreenConnect General
8.4
HIGH
EPSS
84.0%
2024 CWE-22 2 PoCs

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

CVE-2020-17144
🔥 KEV Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 Windows
8.4
HIGH
EPSS
92.0%
2020 2 PoCs

Microsoft Exchange Remote Code Execution Vulnerability

CVE-2025-8088
🔥 KEV WinRAR Windows
8.4
HIGH
EPSS
8.3%
2025 CWE-35 33 PoCs

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CVE-2024-4761
🔥 KEV Chrome General
8.3
HIGH
EPSS
3.1%
2024 1 PoC

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVE-2025-2783
🔥 KEV Chrome Windows
8.3
HIGH
EPSS
46.9%
2025 2 PoCs

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVE-2024-5274
🔥 KEV Chrome General
8.3
HIGH
EPSS
5.0%
2024 3 PoCs

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2021-22555
🔥 KEV Linux Kernel General
8.3
HIGH
EPSS
86.3%
2021 CWE-787 16 PoCs

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE-2021-27877
🔥 KEV Software Genérico General
8.2
HIGH
EPSS
45.5%
2021 1 PoC

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

CVE-2024-53704
🔥 KEV SonicOS Networking ⚡ nuclei
8.2
HIGH
EPSS
93.9%
2024 CWE-287 1 PoC

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVE-2023-41266
🔥 KEV Software Genérico Web Windows ⚡ nuclei
8.2
HIGH
EPSS
94.2%
2023 1 PoC

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVE-2023-46805
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.4%
2023 8 PoCs

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVE-2023-6549
🔥 KEV NetScaler ADC General ⚡ nuclei
8.2
HIGH
EPSS
76.5%
2023 CWE-119 0 PoCs

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVE-2019-18426
🔥 KEV WhatsApp Desktop Web
8.2
HIGH
EPSS
61.0%
2019 CWE-79 3 PoCs

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

CVE-2021-32648
🔥 KEV october Web ⚡ nuclei
8.2
HIGH
EPSS
93.0%
2021 CWE-287 2 PoCs

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

CVE-2015-2546
🔥 KEV Software Genérico Windows
8.2
HIGH
EPSS
43.5%
2015 1 PoC

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

CVE-2023-27351
🔥 KEV NG General ⚡ nuclei
8.2
HIGH
EPSS
87.0%
2023 CWE-287 0 PoCs

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

CVE-2024-21893
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.3%
2024 2 PoCs

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CVE-2021-27876
🔥 KEV Software Genérico General
8.1
HIGH
EPSS
1.1%
2021 1 PoC

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privile