40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48144
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2023-2259
alfio-event/alf.io General
9.1
CRITICAL
EPSS
0.5%
2023 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVE-2022-39227
python-jwt General
9.1
CRITICAL
EPSS
71.3%
2022 CWE-290 3 PoCs

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVE-2022-42905
Software Genérico General
9.1
CRITICAL
EPSS
6.1%
2022 3 PoCs

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)

CVE-2022-21723
pjproject General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-125 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

CVE-2022-2626
hestiacp/hestiacp General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-266 1 PoC

Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

CVE-2022-32585
R1510 General
9.1
CRITICAL
EPSS
0.7%
2022 CWE-489 1 PoC

A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-6014
mlflow/mlflow General
9.1
CRITICAL
EPSS
0.9%
2023 CWE-598 1 PoC

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

CVE-2024-53553
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2025-24383
Unity General
9.1
CRITICAL
EPSS
1.5%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2023-0877
froxlor/froxlor General
9.1
CRITICAL
EPSS
0.5%
2023 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

CVE-2021-21819
D-Link General
9.1
CRITICAL
EPSS
1.3%
2021 CWE-78 1 PoC

A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-0913
microweber/microweber General
9.1
CRITICAL
EPSS
0.8%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

CVE-2024-46505
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2024 1 PoC

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

CVE-2022-26082
OAS Platform General
9.1
CRITICAL
EPSS
2.7%
2022 CWE-306 1 PoC

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2024-57766
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.

CVE-2021-45496
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2021 1 PoC

NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.

CVE-2019-14418
Software Genérico General
9.1
CRITICAL
EPSS
3.7%
2019 1 PoC

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.

CVE-2021-4110
mruby/mruby General
9.1
CRITICAL
EPSS
0.5%
2021 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference