1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2007-5659
🔥 KEV Software Genérico Web
7.8
HIGH
EPSS
92.9%
2007 1 PoC

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

CVE-2021-42292
🔥 KEV Microsoft Office 2019 General
7.8
HIGH
EPSS
35.5%
2021 1 PoC

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2015-0016
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
92.1%
2015 2 PoCs

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."

CVE-2021-38648
🔥 KEV Open Management Infrastructure General
7.8
HIGH
EPSS
31.8%
2021 1 PoC

Open Management Infrastructure Elevation of Privilege Vulnerability

CVE-2016-0165
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
6.2%
2016 1 PoC

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVE-2021-28310
🔥 KEV Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
54.0%
2021 1 PoC

Win32k Elevation of Privilege Vulnerability

CVE-2018-0802
🔥 KEV Equation Editor General
7.8
HIGH
EPSS
94.1%
2018 7 PoCs

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

CVE-2024-38080
🔥 KEV Windows Server 2022 Windows
7.8
HIGH
EPSS
13.7%
2024 CWE-190 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-20352
🔥 KEV IOS Networking
7.7
HIGH
EPSS
2.7%
2025 CWE-121 1 PoC

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisc

CVE-2018-5430
🔥 KEV TIBCO JasperReports Server Web Cloud
7.7
HIGH
EPSS
41.4%
2018 1 PoC

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Commu

CVE-2016-0752
🔥 KEV Software Genérico Web
7.5
HIGH
EPSS
91.1%
2016 3 PoCs

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CVE-2016-3976
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
76.3%
2016 5 PoCs

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

CVE-2014-0130
🔥 KEV Software Genérico Web
7.5
HIGH
EPSS
52.7%
2014 2 PoCs

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

CVE-2026-20128
🔥 KEV Cisco Catalyst SD-WAN Manager Web Networking
7.5
HIGH
EPSS
0.0%
2026 CWE-257 1 PoC

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manage

CVE-2018-18325
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2018 1 PoC

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CVE-2021-40655
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2021 1 PoC

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CVE-2020-5410
🔥 KEV Spring Cloud Config Web Cloud ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2020 CWE-23 5 PoCs

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

CVE-2018-15811
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2018 1 PoC

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVE-2017-0147
🔥 KEV Windows SMB Windows
7.5
HIGH
EPSS
92.4%
2017 6 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."