40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40510
Software Genérico General
8.2
HIGH
EPSS
9.2%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.

CVE-2022-2313
Trellix Agent (TA) General
8.2
HIGH
EPSS
0.0%
2022 1 PoC

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

CVE-2023-26573
IDWeb General
8.2
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

CVE-2021-21045
Acrobat Reader General
8.2
HIGH
EPSS
0.9%
2021 CWE-284 1 PoC

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper access control vulnerability. An unauthenticated attacker could leverage this vulnerability to elevate privileges in the context of the current user.

CVE-2025-3052
BiosFlashShell General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

CVE-2019-10182
icedtea-web General
8.2
HIGH
EPSS
1.1%
2019 CWE-22 2 PoCs

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

CVE-2022-40261
Aptio General
8.2
HIGH
EPSS
0.1%
2022 CWE-120 1 PoC

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass securi

CVE-2021-37562
Software Genérico General
8.2
HIGH
EPSS
0.6%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).

CVE-2023-43017
Security Verify Access Appliance General
8.2
HIGH
EPSS
0.0%
2023 CWE-295 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

CVE-2025-46067
Software Genérico General
8.2
HIGH
EPSS
0.1%
2025 1 PoC

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

CVE-2023-27326
Desktop General
8.2
HIGH
EPSS
2.8%
2023 CWE-22 2 PoCs

Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitr

CVE-2023-26158
mockjs General
8.2
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the software depends on existence or non-existence of certain attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, toString or valueOf). User controlled inputs inside the extend() method of

CVE-2021-32469
Software Genérico General
8.2
HIGH
EPSS
0.6%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915 Affected Software Versions 7.4.0.0; Out-of-bounds read).

CVE-2020-6105
F2fs-Tools General
8.2
HIGH
EPSS
0.6%
2020 CWE-73 1 PoC

An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-29181
nokogiri General
8.2
HIGH
EPSS
4.2%
2022 CWE-241 1 PoC

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.

CVE-2023-4898
mintplex-labs/anything-llm General
8.2
HIGH
EPSS
0.1%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2017-2895
Mongoose General
8.2
HIGH
EPSS
0.4%
2017 1 PoC

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

CVE-2024-38653
Avalanche General ⚡ nuclei
8.2
HIGH
EPSS
90.7%
2024 0 PoCs

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

CVE-2020-7740
node-pdf-generator General
8.2
HIGH
EPSS
5.5%
2020 1 PoC

This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.

CVE-2023-28324
Ivanti Endpoint Manager General
8.2
HIGH
EPSS
79.9%
2023 1 PoC

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.