40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-37570
Software Genérico General
8.2
HIGH
EPSS
0.6%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

CVE-2022-2313
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.0%
2022 1 PoC

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

CVE-2021-34372
NVIDIA Jetson TX2 series, TX2 NX, AGX Xavier series, Xavier NX General
8.2
HIGH
EPSS
0.1%
2021 1 PoC

Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.

CVE-2022-35876
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` configuration parameters, as used within the `testWifiAP` XCMD handler

CVE-2018-1630
Informix Dynamic Server Enterprise Edition General
8.2
HIGH
EPSS
0.1%
2018 1 PoC

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.

CVE-2018-1634
Informix Dynamic Server Enterprise Edition General
8.2
HIGH
EPSS
0.1%
2018 1 PoC

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.

CVE-2024-0213
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.1%
2024 CWE-120 1 PoC

A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a memory corruption issue in the TA service, which runs as root. This may also result in the disabling of event reporting to ePO, caused by failure to validate input from the file correctly.

CVE-2022-0991
admidio/admidio General
8.2
HIGH
EPSS
0.2%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

CVE-2023-5948
teamamaze/amazefileutilities General
8.2
HIGH
EPSS
0.0%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

CVE-2021-37565
Software Genérico General
8.2
HIGH
EPSS
0.6%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).

CVE-2022-1774
jgraph/drawio General
8.2
HIGH
EPSS
0.9%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.

CVE-2025-32966
dataease General ⚡ nuclei
8.2
HIGH
EPSS
11.2%
2025 CWE-290 0 PoCs

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

CVE-2021-35117
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
8.2
HIGH
EPSS
0.3%
2021 1 PoC

An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2017-3971
Network Security Management (NSM) General
8.2
HIGH
EPSS
0.1%
2017 1 PoC

Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers.

CVE-2023-6779
glibc General
8.2
HIGH
EPSS
0.7%
2023 CWE-122 4 PoCs

An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.

CVE-2023-26133
progressbar.js General
8.2
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.

CVE-2021-26563
DiskStation Manager (DSM) General
8.2
HIGH
EPSS
0.1%
2021 CWE-863 1 PoC

Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors.

CVE-2022-41154
QUARTZ-GOLD General
8.2
HIGH
EPSS
1.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary file deletion. An attacker can send a network request to trigger this vulnerability.

CVE-2023-0975
Trellix Agent General
8.2
HIGH
EPSS
0.0%
2023 CWE-281 1 PoC

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.

CVE-2021-39134
arborist General
8.2
HIGH
EPSS
0.7%
2021 CWE-61 2 PoCs

`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in part, accomplished by resolving dependency specifiers defined in `package.json` manifests for dependencies with a specific name, and nesting folders to resolve conflicting dependencies. When multiple dependencies differ only in the case of their name, Arborist's internal data structu