40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-4949
WebSphere Application Server General
8.2
HIGH
EPSS
0.2%
2020 1 PoC

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.

CVE-2026-38651
Software Genérico General
8.2
HIGH
EPSS
0.0%
2026 2 PoCs

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information

CVE-2026-24063
Software Center General
8.2
HIGH
EPSS
0.0%
2026 CWE-276 1 PoC

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper gets instructed to execute this script. When the bash script is manipulated by an attacker this scenario will lead to privilege escalation.

CVE-2022-43601
OpenImageIO General
8.1
HIGH
EPSS
0.8%
2022 CWE-122 1 PoC

Multiple code execution vulnerabilities exist in the IFFOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to a heap buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.This vulnerability arises when the `ymax` variable is set to 0xFFFF and `m_spec.format` is `TypeDesc::UINT16`

CVE-2024-29153
Software Genérico General
8.1
HIGH
EPSS
0.7%
2024 2 PoCs

A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300 that involves incorrect authorization of LTE NAS messages and leads to downgrading to lower network generations and repeated DDOS.

CVE-2025-25950
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

CVE-2022-29503
Eufy Homebase 2 General
8.1
HIGH
EPSS
0.6%
2022 CWE-119 1 PoC

A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

CVE-2021-20190
jackson-databind General
8.1
HIGH
EPSS
0.5%
2021 CWE-502 1 PoC

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2021-21808
Accusoft General
8.1
HIGH
EPSS
0.4%
2021 CWE-120 1 PoC

A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability.

CVE-2024-2887
Chrome General
8.1
HIGH
EPSS
12.2%
2024 3 PoCs

Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2020-13377
Software Genérico General
8.1
HIGH
EPSS
0.2%
2020 1 PoC

The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and write access to sensitive files.

CVE-2021-3689
yiisoft/yii2 General
8.1
HIGH
EPSS
0.4%
2021 CWE-1241 1 PoC

yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

CVE-2024-36886
Linux General
8.1
HIGH
EPSS
0.3%
2024 9 PoCs

In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183 Read of size 8 at addr ffff88804d2a7c80 by task poc/8034 CPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-debian-1.16.0-5 04/01/2014 Call Trace: <IRQ> __dump_stack linux/lib/dump_stack.c:88 dump_stack_lvl+0xd9/0x1b0 lin

CVE-2024-43425
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
89.3%
2024 3 PoCs

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

CVE-2024-36427
Software Genérico General
8.1
HIGH
EPSS
0.5%
2024 1 PoC

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files via a crafted file request. This can allow code execution via a .xview file.

CVE-2024-35433
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

CVE-2024-43702
Graphics DDK General
8.1
HIGH
EPSS
0.1%
2024 CWE-280 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.

CVE-2020-28593
Cosori General
8.1
HIGH
EPSS
2.0%
2020 CWE-912 2 PoCs

A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-21938
Metasys ADS/ADX/OAS server General
8.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.

CVE-2009-3671
Software Genérico General
8.1
HIGH
EPSS
54.1%
2009 1 PoC

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674.