33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-22666
Dolibarr ERP/CRM Web
8.6
HIGH
EPSS
0.4%
2026 CWE-95 1 PoC

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval().

CVE-2026-35020
Claude Code General
8.6
HIGH
EPSS
0.1%
2026 CWE-78 1 PoC

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharacters into the TERMINAL variable which are interpreted by /bin/sh when the command lookup helper constructs and executes shell commands with shell=true. The vulnerability can be triggered during normal CLI execution as well as via the deep-link handler path, resulting in arbitrary command execution w

CVE-2026-30995
Software Genérico Web Database
8.6
HIGH
EPSS
0.0%
2026 1 PoC

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

CVE-2026-27182
Saturn Remote Mouse Server General
8.6
HIGH
EPSS
0.1%
2026 CWE-306 1 PoC

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

CVE-2026-30284
Software Genérico General
8.6
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2026-3830
Product Filter for WooCommerce by WBW Web Database Windows
8.6
HIGH
EPSS
0.1%
2026 1 PoC

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2026-1505
DIR-615 Web
8.6
HIGH
EPSS
0.7%
2026 CWE-78 1 PoC

A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0309
thorsten/phpmyfaq Web
8.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-37019
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-53740
Screen SFT DAB Series - Compact Radio DAB Transmitter General
8.6
HIGH
EPSS
0.5%
2023 CWE-862 2 PoCs

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

CVE-2023-20020
Cisco BroadWorks Web Networking
8.6
HIGH
EPSS
0.4%
2023 CWE-835 1 PoC

A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition

CVE-2023-0312
thorsten/phpmyfaq Web
8.6
HIGH
EPSS
0.7%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-0302
radareorg/radare2 General
8.6
HIGH
EPSS
0.2%
2023 CWE-75 1 PoC

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.

CVE-2023-3722
Aura Device Services General ⚡ nuclei
8.6
HIGH
EPSS
54.6%
2023 CWE-434 1 PoC

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2023-45612
Ktor General
8.6
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CVE-2023-20159
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
4.3%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-30990
i General
8.6
HIGH
EPSS
0.2%
2023 CWE-94 1 PoC

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.

CVE-2023-32315
🔥 KEV Openfire Web ⚡ nuclei
8.6
HIGH
EPSS
94.4%
2023 CWE-22 13 PoCs

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched i

CVE-2023-26496
Software Genérico General
8.6
HIGH
EPSS
5.2%
2023 1 PoC

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.

CVE-2023-37021
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.