94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-2903
Delphix Networking Cloud
8.5
HIGH
EPSS
0.1%
2025 CWE-268 1 PoC

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.

CVE-2025-39663
Checkmk Web
8.5
HIGH
EPSS
0.1%
2025 CWE-80 1 PoC

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).

CVE-2025-53547
helm DevOps
8.5
HIGH
EPSS
0.0%
2025 CWE-94 1 PoC

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated and this file is written, can be crafted in a way that can cause execution if that same content were in a file that is executed (e.g., a bash.rc file or shell script). If the Chart.lock file is symlinked to one of these files updating dependencies will write the lock file content t

CVE-2025-34190
Print Application General
8.5
HIGH
EPSS
0.0%
2025 CWE-306 1 PoC

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (macOS/Linux client deployments) are vulnerable to an authentication bypass in PrinterInstallerClientService. The service requires root privileges for certain administrative operations, but these checks rely on calls to geteuid(). By preloading a malicious shared object overriding geteuid(), a local attacker can trick the service into believing it is running with root privileges. This bypass enables execution of administrative commands (e.g., enabling debug mode, m

CVE-2025-11702
GitLab DevOps
8.5
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

CVE-2025-13733
BuhoNTFS General
8.5
HIGH
EPSS
0.0%
2025 CWE-732 1 PoC

BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.

CVE-2020-36936
Magic Mouse 2 utilities Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to inject malicious executables and gain elevated system privileges by placing a malicious file in the service path.

CVE-2020-36986
Prey General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system reboot.

CVE-2020-36980
SAntivirus IC Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted executable path to inject malicious files in the service binary path, enabling privilege escalation to system-level permissions.

CVE-2020-37037
AVAST SecureLine General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36903
Selea CarPlateServer (CPS) Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 2 PoCs

Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during application startup or reboot.

CVE-2020-6294
SAP Business Objects Business Intelligence Platform General
8.5
HIGH
EPSS
0.3%
2020 2 PoCs

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

CVE-2020-36935
Service KMSELDI General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges.

CVE-2020-37045
NetBackup General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.

CVE-2020-36928
Brother BRAgent General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

CVE-2020-37047
Deep Instinct Windows Agent Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-37017
CodeMeter General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions.

CVE-2020-37099
Disk Savvy Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to inject malicious executables and escalate privileges.

CVE-2020-36975
Status Monitor 3 General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges.

CVE-2020-6109
Zoom General
8.5
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.