40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-4807
usememos/memos General
8.2
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2024-47773
discourse General
8.2
HIGH
EPSS
7.9%
2024 CWE-610 1 PoC

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without any preloaded data. This issue only affects anonymous visitors of the site. This problem has been patched in the latest version of Discourse. Users are advised to upgrade. Users unable to upgrade should disable anonymous cache by setting the `DISCOURSE_DISABLE_ANON_CACHE` environment variable to a non-empty value.

CVE-2022-0860
cobbler/cobbler General
8.2
HIGH
EPSS
0.7%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

CVE-2022-48475
Control de Ciber General
8.2
HIGH
EPSS
0.7%
2022 CWE-400 1 PoC

Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the print query created by the request.

CVE-2021-26365
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
8.2
HIGH
EPSS
0.2%
2021 1 PoC

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.

CVE-2021-45499
Software Genérico General
8.2
HIGH
EPSS
0.5%
2021 1 PoC

Certain NETGEAR devices are affected by authentication bypass. This affects R6900P before 1.3.3.140, R7000P before 1.3.3.140, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000P before 1.4.2.84, RAX75 before 1.0.3.106, and RAX80 before 1.0.3.106.

CVE-2025-0611
Chrome General
8.2
HIGH
EPSS
0.6%
2025 1 PoC

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-41966
xstream General
8.2
HIGH
EPSS
2.5%
2022 CWE-120 1 PoC

XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only

CVE-2024-10776
SICK InspectorP61x General
8.2
HIGH
EPSS
0.3%
2024 CWE-306 1 PoC

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.

CVE-2025-44177
Software Genérico General ⚡ nuclei
8.2
HIGH
EPSS
9.3%
2025 0 PoCs

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences.

CVE-2021-37563
Software Genérico General
8.2
HIGH
EPSS
0.5%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

CVE-2022-3389
ikus060/rdiffweb General
8.2
HIGH
EPSS
0.6%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.

CVE-2021-37571
Software Genérico General
8.2
HIGH
EPSS
0.4%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds write).

CVE-2025-1533
Armoury Crate General
8.2
HIGH
EPSS
0.1%
2025 CWE-121 1 PoC

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVE-2024-24947
P3-550E General
8.2
HIGH
EPSS
0.5%
2024 CWE-787 1 PoC

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset `0xb68c4` of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to `memset` relies on an attacker-controlled length value and corrupts any trailing heap allocations.

CVE-2021-37712
node-tar General
8.2
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory a

CVE-2021-32468
Software Genérico General
8.2
HIGH
EPSS
1.1%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).

CVE-2021-37561
Software Genérico General
8.2
HIGH
EPSS
0.5%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

CVE-2018-1632
Informix Dynamic Server Enterprise Edition General
8.2
HIGH
EPSS
0.1%
2018 1 PoC

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.

CVE-2018-1633
Informix Dynamic Server Enterprise Edition General
8.2
HIGH
EPSS
0.1%
2018 1 PoC

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.