9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-23568
extend2 General
7.3
HIGH
EPSS
0.5%
2021 1 PoC

The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

CVE-2021-3829
openwhyd/openwhyd General
7.3
HIGH
EPSS
0.2%
2021 CWE-601 1 PoC

openwhyd is vulnerable to URL Redirection to Untrusted Site

CVE-2021-25492
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-787 1 PoC

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.

CVE-2021-32547
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.

CVE-2021-1910
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
7.3
HIGH
EPSS
0.2%
2021 1 PoC

Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-4136
vim/vim General
7.3
HIGH
EPSS
0.3%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-25496
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

CVE-2017-20111
WFM General
7.3
HIGH
EPSS
0.4%
2017 CWE-269 1 PoC

A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2017-20025
Solar-Log General
7.3
HIGH
EPSS
0.3%
2017 CWE-269 1 PoC

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2025-55630
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 when entering the wrong username and password allows attackers to enumerate existing accounts.

CVE-2025-28033
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpTo parameter.

CVE-2025-28021
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 parameters

CVE-2025-35027
Go2 General
7.3
HIGH
EPSS
0.2%
2025 CWE-78 2 PoCs

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script. All Unitree models use firmware derived from the same codebase (MIT Cheetah), and the two major forks are the G1 (humanoid) and Go2 (quadruped) branches.

CVE-2025-9966
P series (P07, P10, P12, P15) General
7.3
HIGH
EPSS
0.0%
2025 CWE-269 2 PoCs

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2025-66834
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.

CVE-2025-1936
Firefox General
7.3
HIGH
EPSS
0.2%
2025 1 PoC

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2025-36604
Unity General ⚡ nuclei
7.3
HIGH
EPSS
17.4%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.

CVE-2025-4134
Avast Business Antivirus General
7.3
HIGH
EPSS
0.1%
2025 CWE-552 1 PoC

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.

CVE-2025-9338
Armoury Crate General
7.3
HIGH
EPSS
0.0%
2025 CWE-119 1 PoC

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

CVE-2025-29621
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.