94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-8414
Simplicity SDK General
9.4
CRITICAL
EPSS
0.0%
2025 CWE-20 1 PoC

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability.

CVE-2025-34055
IP camera, DVR, and NVR Devices General
9.4
CRITICAL
EPSS
1.8%
2025 CWE-78 2 PoCs

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system shell without sanitation allowing attackers to execute commands as the root user.

CVE-2025-9963
P series (P07, P10, P12, P15) General
9.4
CRITICAL
EPSS
0.0%
2025 CWE-22 2 PoCs

A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the system can also be compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2020-8479
Central Licensing System General
9.4
CRITICAL
EPSS
0.7%
2020 CWE-91 1 PoC

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 an

CVE-2020-28434
gitblame General
9.4
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

CVE-2020-35800
Software Genérico General
9.4
CRITICAL
EPSS
1.5%
2020 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects AC2100 before 1.2.0.72, AC2400 before 1.2.0.72, AC2600 before 1.2.0.72, CBK40 before 2.5.0.10, CBR40 before 2.5.0.10, D6000 before 1.0.0.80, D6220 before 1.0.0.60, D6400 before 1.0.0.94, D7000v2 before 1.0.0.62, D7800 before 1.0.3.48, D8500 before 1.0.3.50, DC112A before 1.0.0.48, DGN2200v4 before 1.0.0.114, DM200 before 1.0.0.66, EAX20 before 1.0.0.36, EAX80 before 1.0.1.62, EX2700 before 1.0.1.58, EX3110 before 1.0.1.68, EX3700 before 1.0.0.84, EX3800 before 1.0.0.84, EX3920 before 1.0.0.84, EX

CVE-2020-28437
heroku-env General
9.4
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

CVE-2020-28435
ffmpeg-sdk General
9.4
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

CVE-2020-28453
npos-tesseract General
9.4
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

CVE-2020-26908
Software Genérico General
9.4
CRITICAL
EPSS
0.6%
2020 1 PoC

Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6020 before 1.0.0.42, R6050 before 1.0.1.22, JR6150 before 1.0.1.22, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R69002 before 1.2.0.62, and WNR2020 before 1.1.0.62.

CVE-2011-10010
QuickShare File Server General
9.4
CRITICAL
EPSS
57.9%
2011 CWE-22 5 PoCs

QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writable" option is enabled (default during account creation), this allows attackers to upload arbitrary files to privileged locations such as system32, enabling remote code execution via MOF injection or executable placement.

CVE-2022-0401
yuda-lyu/w-zip General
9.4
CRITICAL
EPSS
0.7%
2022 CWE-22 1 PoC

Path Traversal in NPM w-zip prior to 1.0.12.

CVE-2022-41271
NetWeaver Process Integration Web
9.4
CRITICAL
EPSS
0.8%
2022 CWE-862 1 PoC

An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * S

CVE-2022-0660
microweber/microweber General ⚡ nuclei
9.4
CRITICAL
EPSS
7.5%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-3741
chatwoot/chatwoot General
9.4
CRITICAL
EPSS
0.5%
2022 CWE-307 1 PoC

Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depending on the amount of system resources available, to create a DoS event in the server. These accounts still need to be activated; however, it is possible to identify the output Status Code to separate accounts that are generated and waiting for email verification. \n\nFor the sign in directories, it is possible to brute force login attempts to either login portal, which could lead to account compromise.

CVE-2022-3945
kareadita/kavita General
9.4
CRITICAL
EPSS
1.0%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-3993
kareadita/kavita General
9.4
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-2216
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.

CVE-2022-26833
OAS Platform Web ⚡ nuclei
9.4
CRITICAL
EPSS
92.1%
2022 CWE-306 1 PoC

An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2022-0688
microweber/microweber General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.