Fallos del tipo CWE-94

3732 resultados
CVE-2019-10211HIGHPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unproEPSS 1.9%CVE-2024-5082HIGHNexus Repository 2 - Remote Code ExecutionEPSS 1.9%CVE-2024-21513HIGHVersions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving valuEPSS 1.9%CVE-2024-29014HIGHVulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary cEPSS 1.9%CVE-2025-51482HIGHRemote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to exeEPSS 1.9%CVE-2023-5539MEDIUMMoodle: authenticated remote code execution risk in lessonEPSS 1.9%CVE-2011-10018CRITICALmyBB 1.6.4 Backdoor Arbitrary Command ExecutionEPSS 1.9%CVE-2022-45132CRITICALIn Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 temEPSS 1.9%CVE-2023-29862CRITICALAn issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel EPSS 1.9%CVE-2024-56278CRITICALWordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerabilityEPSS 1.8%CVE-2024-35339CRITICALTenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.EPSS 1.8%CVE-2022-41158HIGHeyoom builder Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-25713HIGHyyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pEPSS 1.8%CVE-2020-17091HIGHMicrosoft Teams Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-27857HIGHAn out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.EPSS 1.8%CVE-2021-23814MEDIUMThis affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the filEPSS 1.8%CVE-2022-40628CRITICALRemote Code Execution Vulnerability in Tacitine FirewallEPSS 1.8%CVE-2025-29631CRITICALGardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow commandEPSS 1.8%CVE-2023-22506HIGHThis High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of BambooEPSS 1.8%CVE-2024-36057CRITICALKoha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qEPSS 1.8%