1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-38856
🔥 KEV Apache OFBiz Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2024 CWE-863 10 PoCs

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

CVE-2020-0601
🔥 KEV Windows Web Windows
8.1
HIGH
EPSS
94.1%
2020 23 PoCs

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

CVE-2014-100005
🔥 KEV Software Genérico Web Networking
8.0
HIGH
EPSS
45.9%
2014 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.

CVE-2025-6204
🔥 KEV DELMIA Apriso General ⚡ nuclei
8.0
HIGH
EPSS
7.2%
2025 CWE-94 0 PoCs

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVE-2019-11539
🔥 KEV Software Genérico General
8.0
HIGH
EPSS
93.9%
2019 5 PoCs

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

CVE-2025-32709
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
0.8%
2025 CWE-416 1 PoC

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2015-0311
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.7%
2015 1 PoC

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

CVE-2025-6218
🔥 KEV WinRAR General
7.8
HIGH
EPSS
6.6%
2025 CWE-22 5 PoCs

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

CVE-2024-36971
🔥 KEV Linux General
7.8
HIGH
EPSS
0.4%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_r

CVE-2021-36955
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
20.7%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-1647
🔥 KEV Microsoft System Center Endpoint Protection General
7.8
HIGH
EPSS
77.4%
2021 2 PoCs

Microsoft Defender Remote Code Execution Vulnerability

CVE-2021-3560
🔥 KEV polkit General
7.8
HIGH
EPSS
9.6%
2021 CWE-863 32 PoCs

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2021-4034
🔥 KEV polkit General
7.8
HIGH
EPSS
88.1%
2021 CWE-787 171 PoCs

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users ad

CVE-2021-36934
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
91.0%
2021 16 PoCs

<p>An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker must have the ability to execute code on a victim system to exploit this vulnerability.</p> <p>After installing this security update, you <em>must</em> manually delete

CVE-2026-31431
🔥 KEV Linux General
7.8
HIGH
EPSS
2.6%
2026 22 PoCs

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE-2021-43226
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.4%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2009-1123
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
5.2%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVE-2009-0557
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
86.4%
2009 1 PoC

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."