9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0845
pytorchlightning/pytorch-lightning General
7.3
HIGH
EPSS
0.3%
2022 CWE-94 1 PoC

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

CVE-2022-1295
alvarotrigo/fullpage.js General
7.3
HIGH
EPSS
0.6%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

CVE-2022-1031
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-3662
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability.

CVE-2022-21658
rust General
7.3
HIGH
EPSS
0.9%
2022 CWE-363 1 PoC

Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling symlink following (CWE-363). An attacker could use this security issue to trick a privileged program into deleting files and directories the attacker couldn't otherwise access or delete. Rust 1.0.0 through Rust 1.58.0 is affected by this vulnerability with 1.58.1 containing a patch. Note that the following build targets don't

CVE-2022-21797
joblib General
7.3
HIGH
EPSS
0.3%
2022 1 PoC

The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

CVE-2022-3667
Bento4 General
7.3
HIGH
EPSS
0.6%
2022 CWE-119 1 PoC

A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212007.

CVE-2024-45257
Software Genérico General
7.3
HIGH
EPSS
58.0%
2024 1 PoC

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

CVE-2025-70994
Software Genérico General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal forgery after a local attacker intercepts any legitimate key fob transmission, allowing for complete unauthorized vehicle operation via a replay attack.

CVE-2024-46507
Software Genérico General ⚡ nuclei
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

CVE-2024-45491
Software Genérico General
7.3
HIGH
EPSS
1.1%
2024 1 PoC

An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2026-25615
Blesta General
7.2
HIGH
EPSS
0.0%
2026 CWE-502 1 PoC

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.

CVE-2026-23750
Pouch General
7.2
HIGH
EPSS
0.0%
2026 CWE-122 1 PoC

Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the first fragment, then appends subsequent fragments using memcpy() without verifying that sufficient capacity remains. An adjacent BLE client can send unauthenticated fragments whose combined size exceeds the allocated buffer, causing a heap overflow and crash; integrity impact is also possible due to memory corruption.

CVE-2026-0834
Archer C20 v6.0, Archer AX53 v1.0 General
7.2
HIGH
EPSS
0.0%
2026 CWE-290 1 PoC

Logic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to execute administrative commands including factory reset and device reboot without credentials. Attackers on the adjacent network can remotely trigger factory resets and reboots without credentials, causing configuration loss and interruption of device availability. This issue affects Archer C20 v6.0 < V6_251031, Archer C20 v5 <EU_V5_260317 or < US_V5_260419 Archer AX53 v1.0 < V1_251215 TL-WR841N v13 < 0.9.1 Build 20231120 Rel.62366

CVE-2023-23772
MBTS Site Controller General
7.2
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

CVE-2023-33631
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelSTList interface at /goform/aspForm.

CVE-2023-33635
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm.

CVE-2023-22659
UR32L General
7.2
HIGH
EPSS
0.7%
2023 CWE-77 2 PoCs

An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-33633
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 2 PoCs

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.