33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-22192
GitLab DevOps
9.9
CRITICAL
EPSS
81.2%
2021 2 PoCs

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to execute arbitrary code on the server.

CVE-2021-21872
Lantronix Web
9.9
CRITICAL
EPSS
3.5%
2021 CWE-78 1 PoC

An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-2447
Secure Global Desktop Database
9.9
CRITICAL
EPSS
1.8%
2021 1 PoC

Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vec

CVE-2021-43821
opencast General
9.9
CRITICAL
EPSS
1.0%
2021 CWE-552 1 PoC

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast 9.10 and 10.6, Opencast would open and include local files during ingests. Attackers could exploit this to include most local files the process has read access to, extracting secrets from the host machine. An attacker would need to have the privileges required to add new media to exp

CVE-2021-21889
Lantronix Web
9.9
CRITICAL
EPSS
4.5%
2021 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-43361
HBYS Database
9.9
CRITICAL
EPSS
0.3%
2021 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

CVE-2017-2917
Circle Web
9.9
CRITICAL
EPSS
4.0%
2017 1 PoC

An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2017-2916
Circle Web
9.9
CRITICAL
EPSS
0.5%
2017 1 PoC

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwritten. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2017-2872
Foscam Indoor IP Camera C1 Series Web
9.9
CRITICAL
EPSS
0.3%
2017 1 PoC

Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A HTTP request can allow for a user to perform a firmware upgrade using a crafted image. Before any firmware upgrades in this image are flashed to the device, binaries as well as arguments to shell commands contained in the image are executed with elevated privileges.

CVE-2017-2890
Circle Web
9.9
CRITICAL
EPSS
6.5%
2017 1 PoC

An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request trigger this vulnerability.

CVE-2017-2898
Circle General
9.9
CRITICAL
EPSS
0.5%
2017 1 PoC

An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be installed in the device resulting in arbitrary code execution. An attacker can send a series of packets to trigger this vulnerability.

CVE-2025-29972
Azure Storage Resource Provider (SRP) Cloud
9.9
CRITICAL
EPSS
5.7%
2025 CWE-918 2 PoCs

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

CVE-2025-20333
🔥 KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) Software Web Networking
9.9
CRITICAL
EPSS
25.1%
2025 CWE-120 1 PoC

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complet

CVE-2025-2605
MB-Secure General
9.9
CRITICAL
EPSS
0.8%
2025 CWE-78 2 PoCs

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.

CVE-2025-12419
Mattermost General
9.9
CRITICAL
EPSS
0.1%
2025 CWE-303 1 PoC

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

CVE-2025-20124
Cisco Identity Services Engine Software Web Networking
9.9
CRITICAL
EPSS
8.3%
2025 CWE-502 1 PoC

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected API. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges. Note:&nbsp;To successfully exploit this vulnerability, the attacker must have valid read-only administr

CVE-2025-42957
SAP S/4HANA (Private Cloud or On-Premise) Cloud
9.9
CRITICAL
EPSS
0.1%
2025 CWE-94 2 PoCs

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

CVE-2025-24016
🔥 KEV wazuh Web ⚡ nuclei
9.9
CRITICAL
EPSS
93.5%
2025 CWE-502 8 PoCs

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anyb

CVE-2025-32583
PDF 2 Post General
9.9
CRITICAL
EPSS
0.4%
2025 CWE-94 2 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post pdf2post allows Remote Code Inclusion.This issue affects PDF 2 Post: from n/a through <= 2.4.0.

CVE-2025-46066
Software Genérico General
9.9
CRITICAL
EPSS
0.2%
2025 1 PoC

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges