40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-34217
TN-5900 Series General
8.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-23464
Media Control Panel General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

CVE-2023-50807
Software Genérico General
8.1
HIGH
EPSS
0.3%
2023 2 PoCs

A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

CVE-2021-36801
Akaunting General
8.1
HIGH
EPSS
0.3%
2021 CWE-639 1 PoC

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.

CVE-2024-28735
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

CVE-2024-57174
Software Genérico General
8.1
HIGH
EPSS
0.3%
2024 1 PoC

A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and point its wildcard DNS entry to an attacker-controlled IP address, making it possible to access sensitive information.

CVE-2025-64729
Process Optimization General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.

CVE-2023-2942
openemr/openemr General
8.1
HIGH
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2024-6377
3DSwymer General
8.1
HIGH
EPSS
0.4%
2024 CWE-601 1 PoC

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.

CVE-2025-58075
Mattermost General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

CVE-2023-46694
Software Genérico General
8.1
HIGH
EPSS
9.1%
2023 1 PoC

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

CVE-2016-1762
Software Genérico General
8.1
HIGH
EPSS
4.3%
2016 3 PoCs

The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

CVE-2016-8706
Memcached General
8.1
HIGH
EPSS
51.8%
2016 1 PoC

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

CVE-2023-52043
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.

CVE-2023-5395
Experion Server General
8.1
HIGH
EPSS
1.2%
2023 CWE-121 1 PoC

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2021-41192
redash General ⚡ nuclei
8.1
HIGH
EPSS
79.6%
2021 CWE-1188 0 PoCs

Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. This issue only affects installations where the `REDASH_COOKIE_SECRET or REDASH_SECRET_KEY` environment variables have not been explicitly set. This issue does not affect users of the official Reda

CVE-2023-32284
ImageGear General
8.1
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2019-18568
Antivirus Free Antivirus General
8.1
HIGH
EPSS
0.1%
2019 CWE-680 1 PoC

Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.

CVE-2024-34393
Software Genérico General
8.1
HIGH
EPSS
2.3%
2024 CWE-843 1 PoC

libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).