2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-1999-1588
Software Genérico General
9.8
CRITICAL
EPSS
18.2%
1999 1 PoC

Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.

CVE-2025-70220
Software Genérico General
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

CVE-2024-36057
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by an attacker and is directly included in a system command, i.e., an attack can occur via malicious filenames after uploading a .zip file and clicking Process Images.

CVE-2023-36480
aerospike-client-java General
9.8
CRITICAL
EPSS
3.8%
2023 CWE-502 1 PoC

The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is ru

CVE-2025-70226
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

CVE-2024-38612
Linux General
9.8
CRITICAL
EPSS
0.2%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregister_family() isn't called. This issue exist since commit 46738b1317e1 ("ipv6: sr: add option to control lwtunnel support"), and commit 5559cea2d5aa ("ipv6: sr: fix possible use-after-free and null-ptr-deref") replaced unregister_pernet_subsys() with genl_unregister_family() in this error path.

CVE-2025-70223
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

CVE-2026-45185
Exim General
9.8
CRITICAL
EPSS
0.1%
2026 CWE-416 1 PoC

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

CVE-2025-70232
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.

CVE-2025-70222
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

CVE-2024-45490
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2024 1 PoC

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

CVE-2023-50257
Fast-DDS General
9.7
CRITICAL
EPSS
0.2%
2023 CWE-284 1 PoC

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, al

CVE-2024-28231
Fast-DDS General
9.7
CRITICAL
EPSS
0.9%
2024 CWE-122 1 PoC

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the process to be terminated remotely. Additionally, the payload_size in the DATA Submessage packet is declared as uint32_t. When a negative number, such as -1, is input into this variable, it results in an Integer Overflow (for example, -1 gets converted to 0xFFFFFFFF). This eventually leads to a heap-buffer-overflow, causing t

CVE-2026-21732
Graphics DDK General
9.6
CRITICAL
EPSS
0.1%
2026 CWE-823 1 PoC

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very large value in switch statements in GPU shader code can cause a segmentation fault in the GPU shader compiler due to an out-of-bounds write access.

CVE-2023-27500
NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) General
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.

CVE-2023-22524
Companion for Mac General
9.6
CRITICAL
EPSS
32.0%
2023 2 PoCs

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

CVE-2023-28131
Expo AuthSession module General
9.6
CRITICAL
EPSS
1.3%
2023 2 PoCs

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-27269
NetWeaver Application Server for ABAP and ABAP Platform General
9.6
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files.  In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.

CVE-2023-6753
mlflow/mlflow General
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

CVE-2023-7018
huggingface/transformers General
9.6
CRITICAL
EPSS
0.2%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.