40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-47202
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2025 2 PoCs

In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes.

CVE-2024-33661
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

CVE-2025-8699
Stored Value Unattended Payment Solution General
9.1
CRITICAL
EPSS
0.0%
2025 CWE-922 2 PoCs

Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers could potentially use this vulnerability to change the balance on the cards and generate money. The account balance is stored on an insecure MiFare Classic NFC card and can be read and written back. By carefully observing changes in card dumps, one can identify fields that store the cash value of the card. Additionally, a checksum can be identified, which is created by XOR-ing the cash and an unknown field with a certain value. By updating the fields accordingly, arbitrary amounts of money can be lo

CVE-2024-38883
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

CVE-2023-2003
Vision1210 General
9.1
CRITICAL
EPSS
0.4%
2023 CWE-506 1 PoC

Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.

CVE-2024-32002
git General
9.1
CRITICAL
EPSS
79.6%
2024 CWE-22 62 PoCs

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is dis

CVE-2025-56231
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2025 1 PoC

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

CVE-2024-37388
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

CVE-2024-37770
Software Genérico General
9.1
CRITICAL
EPSS
11.0%
2024 1 PoC

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

CVE-2022-2064
nocodb/nocodb General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2024-37404
Connect Secure General
9.1
CRITICAL
EPSS
86.0%
2024 1 PoC

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

CVE-2024-0818
paddlepaddle/paddle General
9.1
CRITICAL
EPSS
0.3%
2024 CWE-22 1 PoC

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

CVE-2023-47873
WP Child Theme Generator General ⚡ nuclei
9.1
CRITICAL
EPSS
13.0%
2023 CWE-434 0 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

CVE-2024-36497
WINSelect (Standard + Enterprise) General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-312 2 PoCs

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and disable WINSelect entirely.

CVE-2024-40583
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

CVE-2025-39436
I Draw General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0.

CVE-2025-54887
ruby-jwe General
9.1
CRITICAL
EPSS
0.0%
2025 CWE-354 1 PoC

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can be brute forced, which may result in loss of confidentiality for those JWEs and provide ways to craft arbitrary JWEs. This puts users at risk because JWEs can be modified to decrypt to an arbitrary value, decrypted by observing parsing differences and the GCM internal GHASH key can be recovered. Users are affected by this vulnerability even if they do not use an AES-GCM encryption algorithm for their JWEs. As the GHASH key may have been leaked,

CVE-2024-41713
🔥 KEV Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
94.1%
2024 5 PoCs

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2026-34408
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2026 1 PoC

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if the ID is known.

CVE-2024-25170
Software Genérico General
9.1
CRITICAL
EPSS
1.8%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.