2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-3782
Keycloak General
9.1
CRITICAL
EPSS
0.1%
2022 1 PoC

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

CVE-2022-23066
rbpf General
9.1
CRITICAL
EPSS
0.9%
2022 CWE-682 2 PoCs

In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.

CVE-2022-38168
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2022 1 PoC

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVE-2022-47876
Software Genérico General
9.1
CRITICAL
EPSS
19.1%
2022 1 PoC

The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.

CVE-2022-41912
saml General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-287 1 PoC

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.

CVE-2026-34408
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2026 1 PoC

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.

CVE-2024-27053
Linux General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RCU usage in connect path With lockdep enabled, calls to the connect function from cfg802.11 layer lead to the following warning: ============================= WARNING: suspicious RCU usage 6.7.0-rc1-wt+ #333 Not tainted ----------------------------- drivers/net/wireless/microchip/wilc1000/hif.c:386 suspicious rcu_dereference_check() usage! [...] stack backtrace: CPU: 0 PID: 100 Comm: wpa_supplicant Not tainted 6.7.0-rc1-wt+ #333 Hardware name: Atmel SAMA5 unwind_backtrace from show_stack+0x18/0x1c sho

CVE-2024-35960
Linux General
9.1
CRITICAL
EPSS
2.0%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, create_flow_handle tries hard to find and reference already existing identical rules instead of creating new ones. These two behaviors can result in a situation where create_flow_handle 1) creates a new rule and references it, then 2) in a subsequent step during the same handle creation references it again, resulting in a rule with a

CVE-2024-35845
Linux General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.

CVE-2014-0783
CENTUM CS 3000 General
9.0
UNKNOWN
EPSS
5.3%
2014 CWE-121 2 PoCs

Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

CVE-2026-30282
Software Genérico General
9.0
CRITICAL
EPSS
0.1%
2026 1 PoC

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

CVE-2023-45603
User Submitted Posts – Enable Users to Submit Posts from the Front End General
9.0
CRITICAL
EPSS
2.2%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.

CVE-2023-34192
🔥 KEV Software Genérico General ⚡ nuclei
9.0
CRITICAL
EPSS
89.0%
2023 0 PoCs

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CVE-2023-35085
UniFi Access Points General
9.0
CRITICAL
EPSS
7.0%
2023 1 PoC

An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All UniFi Switches (Version 6.5.32 and earlier) -USW Flex Mini excluded. Mitigation: Update UniFi Access Points to Version 6.5.62 or later. Update the UniFi Switches to Version 6.5.59 or later.

CVE-2023-31475
Software Genérico General
9.0
CRITICAL
EPSS
25.8%
2023 1 PoC

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

CVE-2023-1287
ENOVIA Live Collaboration General
9.0
CRITICAL
EPSS
2.6%
2023 CWE-74 1 PoC

An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

CVE-2023-27830
Software Genérico General
9.0
CRITICAL
EPSS
0.5%
2023 1 PoC

TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when executing a file transfer. This is due to the fact that TightVNC runs in the backend as a high-privileges account.

CVE-2023-21456
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVE-2023-31422
Kibana General
9.0
CRITICAL
EPSS
0.4%
2023 CWE-532 1 PoC

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in t

CVE-2023-0432
DX-2100-L1-CN General
9.0
CRITICAL
EPSS
1.8%
2023 CWE-79 1 PoC

The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.