94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-35021
Claude Code General
8.4
HIGH
EPSS
0.0%
2026 CWE-78 1 PoC

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions into file paths that are interpolated into shell commands executed via execSync. Although the file path is wrapped in double quotes, POSIX shell semantics (POSIX §2.2.3) do not prevent command substitution within double quotes, allowing injected expressions to be evaluated and resulting in arbitrary co

CVE-2026-40499
radare2 General
8.4
HIGH
EPSS
0.0%
2026 CWE-78 1 PoC

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section header name field. Attackers can craft a malicious PDB file with specially crafted section names to inject r2 commands that are executed when the idp command processes the file.

CVE-2026-30290
Software Genérico General
8.4
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2026-24882
GnuPG General
8.4
HIGH
EPSS
0.0%
2026 CWE-121 1 PoC

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

CVE-2026-30277
Software Genérico General
8.4
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2026-30287
Software Genérico General
8.4
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2026-30292
Software Genérico General
8.4
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2026-30279
Software Genérico General
8.4
HIGH
EPSS
0.0%
2026 1 PoC

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2023-30691
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

CVE-2023-23771
MBTS Base Radio General
8.4
HIGH
EPSS
0.0%
2023 CWE-259 1 PoC

Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

CVE-2023-5060
librenms/librenms Web
8.4
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

CVE-2023-0299
publify/publify General
8.4
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.

CVE-2023-23774
EBTS/MBTS Base Radio General
8.4
HIGH
EPSS
0.0%
2023 CWE-248 1 PoC

Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.

CVE-2023-31003
Security Verify Access Appliance DevOps
8.4
HIGH
EPSS
0.0%
2023 CWE-59 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: 254658.

CVE-2023-42537
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-21666
Snapdragon General
8.4
HIGH
EPSS
0.1%
2023 CWE-401 1 PoC

Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.

CVE-2023-5607
Trellix Application and Change Control (TACC) General
8.4
HIGH
EPSS
0.5%
2023 CWE-22 1 PoC

An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could lead to an authorised administrator attacker executing arbitrary code through uploading a specially crafted GTI reputation file. The attacker would need the appropriate privileges to access the relevant section of the User Interface. The import logic has been updated to restrict file types and content.

CVE-2023-53940
Codigo Markdown Editor General
8.4
HIGH
EPSS
0.0%
2023 CWE-94 1 PoC

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file is opened.

CVE-2023-30680
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

CVE-2023-41791
Pandora FMS Web
8.4
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed users with low privileges to introduce Javascript executables via a translation string that could affect the integrity of some configuration files. This issue affects Pandora FMS: from 700 through 773.