9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-21677
Confluence Data Center General
8.3
HIGH
EPSS
2.0%
2024 2 PoCs

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommen

CVE-2019-3629
McAfee Enterprise Security Manager (ESM) General
8.3
HIGH
EPSS
1.2%
2019 1 PoC

Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters.

CVE-2019-20760
Software Genérico General
8.3
HIGH
EPSS
0.2%
2019 1 PoC

NETGEAR R9000 devices before 1.0.4.26 are affected by authentication bypass.

CVE-2019-11540
Software Genérico General
8.3
HIGH
EPSS
6.3%
2019 1 PoC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

CVE-2019-10761
vm2 General
8.3
HIGH
EPSS
0.8%
2019 2 PoCs

This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.

CVE-2021-23405
pimcore/pimcore General
8.3
HIGH
EPSS
0.0%
2021 1 PoC

This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.

CVE-2021-26566
Synology DiskStation Manager (DSM) General
8.3
HIGH
EPSS
0.5%
2021 CWE-201 1 PoC

Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers to execute arbitrary commands via inbound QuickConnect traffic.

CVE-2021-22555
🔥 KEV Linux Kernel General
8.3
HIGH
EPSS
86.3%
2021 CWE-787 16 PoCs

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE-2021-27275
ProSAFE Network Management System General
8.3
HIGH
EPSS
59.1%
2021 CWE-22 1 PoC

This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ConfigFileController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose sensitive information or to create a d

CVE-2021-38529
Software Genérico General
8.3
HIGH
EPSS
1.9%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.

CVE-2021-21372
security General
8.3
HIGH
EPSS
1.8%
2021 CWE-20 1 PoC

Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json package list to trigger code execution.

CVE-2021-45637
Software Genérico General
8.3
HIGH
EPSS
0.7%
2021 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6260 before 1.1.0.76, R6800 before 1.2.0.62, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, AC2100 before 1.2.0.62, AC2400 before 1.2.0.62, and AC2600 before 1.2.0.62.

CVE-2021-36198
Entrapass General
8.3
HIGH
EPSS
0.2%
2021 CWE-200 1 PoC

Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.

CVE-2021-42694
Software Genérico General
8.3
HIGH
EPSS
8.2%
2021 4 PoCs

An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can leverage this to inject code via adversarial identifier definitions in upstream software dependencies invoked deceptively in downstream software. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect appli

CVE-2017-3972
Network Security Management (NSM) General
8.3
HIGH
EPSS
0.9%
2017 1 PoC

Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information.

CVE-2017-2797
DMC HTMLFilter General
8.3
HIGH
EPSS
0.3%
2017 1 PoC

An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.

CVE-2017-2799
DMC HTMLFilter General
8.3
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can send or provide a malicious XLS file to trigger this vulnerability.

CVE-2017-15118
Qemu General
8.3
HIGH
EPSS
1.6%
2017 CWE-121 1 PoC

A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.

CVE-2017-2792
DMC HTMLFilter General
8.3
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can provide a malicious xls file to trigger this vulnerability.

CVE-2017-2783
DMC HTMLFilter General
8.3
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter that is shipped with MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious xls file to trigger this vulnerability.