40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0739
answerdev/answer General
8.1
HIGH
EPSS
0.5%
2023 CWE-362 1 PoC

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2018-18600
Software Genérico General
8.1
HIGH
EPSS
2.8%
2018 1 PoC

The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.

CVE-2021-20190
jackson-databind General
8.1
HIGH
EPSS
0.5%
2021 CWE-502 1 PoC

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2019-3638
Web Gateway(MWG) General
8.1
HIGH
EPSS
1.0%
2019 1 PoC

Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.

CVE-2023-45842
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.

CVE-2025-27363
🔥 KEV FreeType General
8.1
HIGH
EPSS
70.8%
2025 5 PoCs

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

CVE-2025-10101
Antivirus General
8.1
HIGH
EPSS
0.0%
2025 CWE-122 1 PoC

Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of Service of antivirus protection. This issue affects Antivirus: from 15.7 before 3.9.2025.

CVE-2023-34998
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-5403
Experion Server General
8.1
HIGH
EPSS
1.0%
2023 CWE-121 1 PoC

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2025-6435
Firefox General
8.1
HIGH
EPSS
0.5%
2025 1 PoC

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVE-2023-3314
Enterprise Security Manager General
8.1
HIGH
EPSS
0.6%
2023 CWE-78 1 PoC

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

CVE-2021-35110
Snapdragon Connectivity, Snapdragon Mobile General
8.1
HIGH
EPSS
0.1%
2021 1 PoC

Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-23412
gitlogplus General
8.1
HIGH
EPSS
4.4%
2021 1 PoC

All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

CVE-2023-5353
salesagility/suitecrm General
8.1
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2025-69618
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 1 PoC

An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information.

CVE-2023-31435
Software Genérico General
8.1
HIGH
EPSS
0.6%
2023 2 PoCs

Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing functions directly.

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2021-36801
Akaunting General
8.1
HIGH
EPSS
0.3%
2021 CWE-639 1 PoC

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.