33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2018-25241
VPN Browser+ Networking
8.7
HIGH
EPSS
0.1%
2018 CWE-306 1 PoC

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application.

CVE-2018-25193
Mongoose Web Server General
8.7
HIGH
EPSS
0.1%
2018 CWE-1188 1 PoC

Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unavailability.

CVE-2018-25181
Musicco General
8.7
HIGH
EPSS
1.1%
2018 CWE-22 1 PoC

Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download them as ZIP files.

CVE-2018-25164
EverSync General
8.7
HIGH
EPSS
0.1%
2018 CWE-552 1 PoC

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application data and credentials.

CVE-2018-25178
Easyndexer Web
8.7
HIGH
EPSS
0.5%
2018 CWE-22 1 PoC

Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files.

CVE-2018-25136
Brickstream 3D+ General
8.7
HIGH
EPSS
0.1%
2018 CWE-306 2 PoCs

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can retrieve video stream images by directly accessing multiple image endpoints like middleImage.jpg, rightimage.jpg, and leftimage.jpg.

CVE-2018-25125
DL4322D Networking
8.7
HIGH
EPSS
0.3%
2018 CWE-120 1 PoC

Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger a denial of service. After logging in to the FTP service, sending an FTP command such as ABOR with an excessively long argument causes the service, and in practice the router, to crash or become unresponsive, resulting in a loss of availability for the device and connected users.

CVE-2018-25124
PacsOne Server Web
8.7
HIGH
EPSS
1.2%
2018 CWE-22 1 PoC

PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote unauthenticated attacker to read arbitrary files via the 'nocache.php' endpoint with a crafted 'path' parameter. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.

CVE-2018-25169
AMPPS Web
8.7
HIGH
EPSS
0.2%
2018 CWE-1188 1 PoC

AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malformed data to the default HTTP port. Attackers can establish multiple socket connections and transmit invalid payloads to exhaust server resources and cause service unavailability.

CVE-2018-25141
FLIR Thermal Traffic Cameras General
8.7
HIGH
EPSS
0.2%
2018 CWE-306 2 PoCs

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.

CVE-2018-25137
FLIR Brickstream 3D+ Web
8.7
HIGH
EPSS
0.1%
2018 CWE-306 2 PoCs

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.

CVE-2018-25148
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Remote Root Exploit Networking
8.7
HIGH
EPSS
0.4%
2018 CWE-266 2 PoCs

Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.

CVE-2010-10012
httpdasm Web Windows
8.7
HIGH
EPSS
61.8%
2010 CWE-22 3 PoCs

A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker can escape the web root and access sensitive files outside of the intended directory.

CVE-2010-20109
Spam & Virus Firewall Networking
8.7
HIGH
EPSS
55.3%
2010 CWE-22 2 PoCs

Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October 2010, contain a path traversal vulnerability in the view_help.cgi endpoint. The locale parameter fails to properly sanitize user input, allowing attackers to inject traversal sequences and null-byte terminators to access arbitrary files on the underlying system. By exploiting this flaw, unauthenticated remote attackers can retrieve sensitive configuration files such as /mail/snapshot/config.snapshot, potentially exposing credentials, internal settings, and other critical data

CVE-2010-10014
Odin Secure FTP General
8.7
HIGH
EPSS
61.3%
2010 CWE-121 2 PoCs

Odin Secure FTP <= 4.1 is vulnerable to a stack-based buffer overflow when parsing directory listings received in response to an FTP LIST command. A malicious FTP server can send an overly long filename in the directory listing, which overflows a fixed-size stack buffer in the client and overwrites the Structured Exception Handler (SEH). This allows remote attackers to execute arbitrary code on the client system.

CVE-2005-10004
Cacti Web
8.7
HIGH
EPSS
58.0%
2005 CWE-78 3 PoCs

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

CVE-2011-10029
Solar FTP Server General
8.7
HIGH
EPSS
48.8%
2011 CWE-134 2 PoCs

Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

CVE-2011-10028
RealArcade ActiveX Windows
8.7
HIGH
EPSS
62.6%
2011 CWE-623 4 PoCs

The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

CVE-2011-10009
S40 CMS Web
8.7
HIGH
EPSS
48.4%
2011 CWE-22 4 PoCs

S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sanitized, allowing attackers to traverse the file system and access arbitrary files outside the web root. This can be exploited remotely without authentication by appending traversal sequences and a null byte to bypass file extension checks.

CVE-2011-10014
San Andreas Multiplayer General
8.7
HIGH
EPSS
2.3%
2011 CWE-121 3 PoCs

GTA San Andreas Multiplayer (SA-MP) server version 0.3.1.1 is vulnerable to a stack-based buffer overflow triggered by parsing a malformed server.cfg configuration file. The vulnerability allows local attackers to execute arbitrary code when the server binary (samp-server.exe) processes a crafted echo directive containing excessive input. The original 'sa-mp.com' site is defunct, but the community maintains mirrors and forks that may be vulnerable.