9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-54525
Mattermost Confluence Plugin General
7.5
HIGH
EPSS
0.1%
2025 CWE-1287 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.

CVE-2025-28228
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
6.3%
2025 1 PoC

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

CVE-2025-26781
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of RLC AM PDUs leads to a Denial of Service.

CVE-2025-60751
Software Genérico General
7.5
HIGH
EPSS
0.6%
2025 1 PoC

GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

CVE-2025-48050
DOMPurify General
7.5
HIGH
EPSS
0.4%
2025 CWE-24 1 PoC

In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression" occurs "in a development helper script which starts a local web server if needed and must be manually started."

CVE-2025-49184
Field Analytics General
7.5
HIGH
EPSS
0.4%
2025 CWE-200 1 PoC

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.

CVE-2025-59439
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123. Incorrect handling of NAS Registration messages leads to a Denial of Service because of Improper Handling of Exceptional Conditions.

CVE-2020-28496
three General
7.5
HIGH
EPSS
1.4%
2020 2 PoCs

This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blank (n) { var ret = "rgb(" for (var i = 0; i < n; i++) { ret += " " } return ret + ""; } var Color = three.Color var time = Date.now(); new Color(build_blank(50000)) var time_cost = Date.now() - time; console.log(time_cost+" ms")

CVE-2020-6087
Allen Bradley General
7.5
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability If the ANSI Extended Symbol Segment Sub-Type is supplied, the device treats the byte following as the Data Size in words. When this value represents a size greater than what remains in the packet data, the device enters a fault state where communication with the devi

CVE-2020-11268
Snapdragon Auto, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

CVE-2020-8495
Software Genérico General
7.5
HIGH
EPSS
4.7%
2020 2 PoCs

In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.

CVE-2020-6088
Allen-Bradley General
7.5
HIGH
EPSS
0.2%
2020 CWE-120 2 PoCs

An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2020-10957
Software Genérico General
7.5
HIGH
EPSS
8.1%
2020 2 PoCs

In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

CVE-2020-6369
CA Introscope Enterprise Manager (Affected products: SAP Solution Manager and SAP Focused Run) General
7.5
HIGH
EPSS
1.2%
2020 1 PoC

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service.

CVE-2020-7682
marked-tree General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.

CVE-2020-7665
github.com/u-root/u-root/pkg/uzip General
7.5
HIGH
EPSS
0.1%
2020 1 PoC

This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.

CVE-2020-26869
PcVue General
7.5
HIGH
EPSS
0.5%
2020 CWE-200 1 PoC

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.

CVE-2020-16947
Microsoft Office 2019 General
7.5
HIGH
EPSS
45.4%
2020 4 PoCs

<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted tha