9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-33077
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

CVE-2022-45124
KingHistorian General
7.5
HIGH
EPSS
5.6%
2022 CWE-200 2 PoCs

An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff network traffic to leverage this vulnerability.

CVE-2022-1284
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

CVE-2022-25895
lite-dev-server General
7.5
HIGH
EPSS
1.4%
2022 1 PoC

All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

CVE-2022-32485
CPG BIOS General
7.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-41684
OpenImageIO General
7.5
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-38840
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
58.1%
2022 1 PoC

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.

CVE-2022-24412
PowerScale OneFS General
7.5
HIGH
EPSS
0.5%
2022 CWE-229 1 PoC

Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.

CVE-1999-1568
Software Genérico General
7.5
HIGH
EPSS
1.7%
1999 1 PoC

Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

CVE-2006-4574
Software Genérico General
7.5
HIGH
EPSS
6.8%
2006 1 PoC

Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

CVE-2025-70242
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

CVE-2025-70227
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.

CVE-2024-6119
OpenSSL General
7.5
HIGH
EPSS
14.3%
2024 CWE-843 1 PoC

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that termina

CVE-2025-70238
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

CVE-2025-70886
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

CVE-2025-70252
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

CVE-2024-46508
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

CVE-2025-70241
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

CVE-2025-70249
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

CVE-2026-38728
Software Genérico General
7.5
HIGH
EPSS
0.1%
2026 1 PoC

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components