9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-39214
Zoom SDK's General
7.6
HIGH
EPSS
0.4%
2023 CWE-749 1 PoC

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-3819
pimcore/pimcore General
7.6
HIGH
EPSS
0.0%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-26075
Software Genérico General
7.6
HIGH
EPSS
0.9%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Service Area List.

CVE-2024-41630
Software Genérico General
7.6
HIGH
EPSS
2.5%
2024 1 PoC

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

CVE-2024-28247
pi-hole General
7.6
HIGH
EPSS
7.1%
2024 CWE-200 1 PoC

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files arbitrarily, and because the application runs from behind, reading files is done as a privileged user.If the URL that is in the list of "Adslists" begins with "file*" it is understood that it is updating from a local file, on the other hand if it does not begin with "file*" depending on the state of the response it does one thing or another. The pr

CVE-2024-32399
Software Genérico General ⚡ nuclei
7.6
HIGH
EPSS
83.5%
2024 2 PoCs

Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

CVE-2024-3841
Chrome General
7.6
HIGH
EPSS
0.4%
2024 1 PoC

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)

CVE-2024-25652
Secret Server General
7.6
HIGH
EPSS
0.3%
2024 CWE-287 2 PoCs

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

CVE-2024-42464
upKeeper Manager General
7.6
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-27705
Software Genérico General
7.6
HIGH
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

CVE-2024-1764
Server General
7.6
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances

CVE-2024-36443
Software Genérico General
7.6
HIGH
EPSS
0.5%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

CVE-2024-21689
Bamboo Data Center General
7.6
HIGH
EPSS
37.7%
2024 3 PoCs

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one

CVE-2019-20761
Software Genérico General
7.6
HIGH
EPSS
0.3%
2019 1 PoC

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

CVE-2019-9506
BR/EDR General
7.6
HIGH
EPSS
4.5%
2019 CWE-310 2 PoCs

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

CVE-2019-12266
Cam Pan v2 General
7.6
HIGH
EPSS
0.6%
2019 CWE-121 1 PoC

Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2019-5024
Capsule Technologies SmartLinx Neuron 2 General
7.6
HIGH
EPSS
0.0%
2019 CWE-693 1 PoC

A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this vulnerability.

CVE-2021-3666
fiznool/body-parser-xml General
7.6
HIGH
EPSS
0.4%
2021 CWE-1321 1 PoC

body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-33601
F-Secure Internet Gatekeeper General
7.6
HIGH
EPSS
0.7%
2021 1 PoC

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

CVE-2021-33699
SAP Fiori Client Native Mobile for Android General
7.6
HIGH
EPSS
2.2%
2021 1 PoC

Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.