465 vulnerabilidades · General · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2022-28810
🔥 KEV Software Genérico General
6.8
MEDIUM
EPSS
90.7%
2022 2 PoCs

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CVE-2021-22600
🔥 KEV Kernel General
6.6
MEDIUM
EPSS
0.2%
2021 CWE-415 2 PoCs

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

CVE-2023-36761
🔥 KEV Microsoft Office 2019 General
6.5
MEDIUM
EPSS
5.5%
2023 CWE-20 1 PoC

Microsoft Word Information Disclosure Vulnerability

CVE-2019-5786
🔥 KEV Chrome General
6.5
MEDIUM
EPSS
89.4%
2019 1 PoC

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2019-6693
🔥 KEV FortiGate General
6.5
MEDIUM
EPSS
72.2%
2019 3 PoCs

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CVE-2020-11652
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
93.7%
2020 9 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

CVE-2016-3351
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
45.4%
2016 1 PoC

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

CVE-2016-9563
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
58.8%
2016 1 PoC

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

CVE-2009-3960
🔥 KEV Software Genérico General
6.5
MEDIUM
EPSS
90.4%
2009 1 PoC

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

CVE-2021-25395
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.2%
2021 CWE-362 1 PoC

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVE-2021-25394
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.4%
2021 CWE-416 1 PoC

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVE-2021-1906
🔥 KEV Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
6.2
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-25369
🔥 KEV Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.2%
2021 CWE-200 2 PoCs

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

CVE-2021-25372
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
1.8%
2021 2 PoCs

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

CVE-2021-25370
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.5%
2021 2 PoCs

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

CVE-2021-25371
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
1.6%
2021 CWE-912 2 PoCs

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

CVE-2023-4211
🔥 KEV Midgard GPU Kernel Driver General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVE-2023-41991
🔥 KEV iOS and iPadOS General
5.5
MEDIUM
EPSS
3.5%
2023 1 PoC

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2020-27950
🔥 KEV watchOS General
5.5
MEDIUM
EPSS
43.8%
2020 2 PoCs

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

CVE-2020-9934
🔥 KEV iOS General
5.5
MEDIUM
EPSS
2.4%
2020 1 PoC

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.