40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-34392
Software Genérico General
8.1
HIGH
EPSS
3.2%
2024 CWE-843 1 PoC

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.

CVE-2024-3157
Chrome General
8.1
HIGH
EPSS
0.7%
2024 1 PoC

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVE-2022-25900
git-clone General
8.1
HIGH
EPSS
4.7%
2022 1 PoC

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

CVE-2022-42272
NVIDIA DGX servers General
8.1
HIGH
EPSS
0.8%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may lead to code execution, denial of service or escalation of privileges.

CVE-2024-11700
Firefox General
8.1
HIGH
EPSS
0.3%
2024 1 PoC

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVE-2022-41674
Software Genérico General
8.1
HIGH
EPSS
0.5%
2022 2 PoCs

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

CVE-2020-10061
zephyr General
8.1
HIGH
EPSS
0.1%
2020 CWE-119 1 PoC

Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.

CVE-2024-39890
Software Genérico General
8.1
HIGH
EPSS
0.8%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300. The baseband software does not properly check the length specified by the CC (Call Control). This can lead to an Out-of-Bounds write.

CVE-2024-36444
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 2 PoCs

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

CVE-2022-1650
eventsource/eventsource General
8.1
HIGH
EPSS
1.5%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

CVE-2020-28592
Cosori General
8.1
HIGH
EPSS
4.1%
2020 CWE-120 2 PoCs

A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2024-56883
Software Genérico General
8.1
HIGH
EPSS
3.1%
2024 2 PoCs

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the user interface. To do this, a valid request to create a course simply needs to be modified, so that the current user ID in the "id" parameter is replaced with the ID of another user.

CVE-2024-27804
iOS and iPadOS General
8.1
HIGH
EPSS
4.2%
2024 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.

CVE-2021-21810
AT&T Labs General
8.1
HIGH
EPSS
0.6%
2021 CWE-122 1 PoC

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21772
3MF General
8.1
HIGH
EPSS
1.7%
2021 2 PoCs

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21773
Accusoft General
8.1
HIGH
EPSS
0.2%
2021 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the TIFF header count-processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-51329
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 1 PoC

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

CVE-2020-28468
pwntools General
8.1
HIGH
EPSS
4.8%
2020 1 PoC

This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.

CVE-2024-41967
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.3%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

CVE-2024-5565
Software Genérico General
8.1
HIGH
EPSS
5.1%
2024 CWE-94 1 PoC

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.