465 vulnerabilidades · General · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2016-4655
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
81.7%
2016 1 PoC

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

CVE-2014-0196
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
48.6%
2014 5 PoCs

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

CVE-2021-30657
🔥 KEV macOS General
5.5
MEDIUM
EPSS
83.1%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVE-2024-50302
🔥 KEV Linux General
5.5
MEDIUM
EPSS
1.7%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

CVE-2021-27562
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
44.5%
2021 1 PoC

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CVE-2023-6548
🔥 KEV NetScaler ADC General
5.5
MEDIUM
EPSS
8.3%
2023 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CVE-2025-55177
🔥 KEV WhatsApp Desktop for Mac General
5.4
MEDIUM
EPSS
0.7%
2025 1 PoC

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.

CVE-2021-26086
🔥 KEV Jira Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.2%
2021 3 PoCs

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

CVE-2021-26085
🔥 KEV Confluence Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.0%
2021 3 PoCs

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2010-0738
🔥 KEV Software Genérico General
5.3
MEDIUM
EPSS
91.5%
2010 1 PoC

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CVE-2023-41763
🔥 KEV Skype for Business Server 2015 CU13 General ⚡ nuclei
5.3
MEDIUM
EPSS
16.5%
2023 CWE-918 0 PoCs

Skype for Business Elevation of Privilege Vulnerability

CVE-2022-22265
🔥 KEV Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-703 1 PoC

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2025-47827
🔥 KEV Software Genérico General
4.6
MEDIUM
EPSS
0.9%
2025 1 PoC

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2023-21492
🔥 KEV Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

CVE-2021-25337
🔥 KEV Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.8%
2021 CWE-269 2 PoCs

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CVE-2017-0059
🔥 KEV Internet Explorer General
4.3
MEDIUM
EPSS
83.6%
2017 3 PoCs

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.