40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-36801
Akaunting General
8.1
HIGH
EPSS
0.3%
2021 CWE-639 1 PoC

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.

CVE-2020-26226
semantic-release General
8.1
HIGH
EPSS
0.2%
2020 CWE-116 1 PoC

In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.

CVE-2020-5330
Dell PowerConnect General
8.1
HIGH
EPSS
17.2%
2020 CWE-200 1 PoC

Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints.

CVE-2025-56224
Software Genérico General
8.1
HIGH
EPSS
0.0%
2025 1 PoC

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

CVE-2025-58075
Mattermost General
8.1
HIGH
EPSS
0.0%
2025 CWE-862 1 PoC

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

CVE-2023-50123
Software Genérico General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to perform a brute force on the SMS authentication, to bring the alarm system to a disarmed state.

CVE-2025-10854
Software Genérico General
8.1
HIGH
EPSS
0.1%
2025 CWE-61 1 PoC

The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is intended to prevent path traversal vulnerabilities by ensuring safe filenames, it does not account for symbolic links within the tar file. An attacker is able to write a file anywhere in the filesystem when txtai is used to load untrusted embedding indices

CVE-2023-51073
Software Genérico General
8.1
HIGH
EPSS
26.0%
2023 1 PoC

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

CVE-2023-40463
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-798 1 PoC

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

CVE-2023-45840
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package.

CVE-2023-20894
VMware vCenter Server (vCenter Server) General
8.1
HIGH
EPSS
45.9%
2023 1 PoC

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

CVE-2023-31182
EasyTor Applications General
8.1
HIGH
EPSS
0.1%
2023 CWE-639 1 PoC

EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified method.

CVE-2007-5927
Software Genérico General
8.1
HIGH
EPSS
0.6%
2007 1 PoC

Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.

CVE-2026-20761
SmartServer IoT General
8.1
HIGH
EPSS
0.4%
2026 CWE-77 2 PoCs

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

CVE-2026-4434
Server General
8.1
HIGH
EPSS
0.0%
2026 CWE-295 1 PoC

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

CVE-2026-24450
LibRaw General
8.1
HIGH
EPSS
0.1%
2026 CWE-190 2 PoCs

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2026-20884
LibRaw General
8.1
HIGH
EPSS
0.1%
2026 CWE-190 2 PoCs

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-22752
Software Genérico General
8.1
HIGH
EPSS
0.6%
2024 1 PoC

Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.

CVE-2019-5144
Kakadu Software General
8.1
HIGH
EPSS
3.2%
2019 CWE-191 1 PoC

An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.