40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-0763
mintplex-labs/anything-llm General
8.1
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

CVE-2010-3962
🔥 KEV Software Genérico General
8.1
HIGH
EPSS
88.9%
2010 3 PoCs

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.

CVE-2023-0919
kareadita/kavita General
8.1
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.

CVE-2025-48466
Advantech Wireless Sensing and Equipment (WISE) General
8.1
HIGH
EPSS
0.2%
2025 1 PoC

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

CVE-2023-50447
Software Genérico General
8.1
HIGH
EPSS
0.7%
2023 2 PoCs

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

CVE-2023-26984
Software Genérico General
8.1
HIGH
EPSS
0.8%
2023 1 PoC

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

CVE-2025-27363
🔥 KEV FreeType General
8.1
HIGH
EPSS
70.8%
2025 5 PoCs

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVE-2021-21832
Disc General
8.1
HIGH
EPSS
0.6%
2021 CWE-680 1 PoC

A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2010-0248
Software Genérico General
8.1
HIGH
EPSS
78.4%
2010 1 PoC

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

CVE-2025-69618
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information.

CVE-2023-5401
Experion Server General
8.1
HIGH
EPSS
1.6%
2023 CWE-121 1 PoC

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2021-35110
Snapdragon Connectivity, Snapdragon Mobile General
8.1
HIGH
EPSS
0.1%
2021 1 PoC

Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile

CVE-2021-21810
AT&T Labs General
8.1
HIGH
EPSS
0.6%
2021 CWE-122 1 PoC

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-0739
answerdev/answer General
8.1
HIGH
EPSS
0.5%
2023 CWE-362 1 PoC

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2021-36801
Akaunting General
8.1
HIGH
EPSS
0.3%
2021 CWE-639 1 PoC

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.

CVE-2018-18600
Software Genérico General
8.1
HIGH
EPSS
2.8%
2018 1 PoC

The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

CVE-2025-6435
Firefox General
8.1
HIGH
EPSS
0.5%
2025 1 PoC

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVE-2024-28735
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2023-45842
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.