40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-54794
claude-code General
7.7
HIGH
EPSS
0.1%
2025 CWE-22 1 PoC

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it possible to bypass directory restrictions and access files outside the CWD. Successful exploitation depends on the presence of (or ability to create) a directory with the same prefix as the CWD and the ability to add untrusted content into a Claude Code context window. This is fixed in version 0.2.111.

CVE-2024-20895
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2024 1 PoC

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

CVE-2020-1711
QEMU General
7.7
HIGH
EPSS
0.6%
2020 CWE-122 2 PoCs

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.

CVE-2024-27155
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.7
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.

CVE-2024-36495
WINSelect (Standard + Enterprise) General
7.7
HIGH
EPSS
0.0%
2024 CWE-276 2 PoCs

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect Enterprise configuration file is: C:\ProgramData\Faronics\StorageSpace\WS\WINSelect.wsd

CVE-2024-1163
mbloch/mapshaper General
7.7
HIGH
EPSS
0.1%
2024 CWE-22 1 PoC

The attacker may exploit a path traversal vulnerability leading to information disclosure.

CVE-2024-40676
Android General
7.7
HIGH
EPSS
0.1%
2024 3 PoCs

In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2022-1899
radareorg/radare2 General
7.7
HIGH
EPSS
0.5%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2021-4171
janeczku/calibre-web General
7.7
HIGH
EPSS
0.4%
2021 CWE-840 1 PoC

calibre-web is vulnerable to Business Logic Errors

CVE-2021-21953
Anker General
7.7
HIGH
EPSS
0.3%
2021 CWE-300 1 PoC

An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.

CVE-2019-16775
cli General
7.7
HIGH
EPSS
0.9%
2019 CWE-61 3 PoCs

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.

CVE-2021-34374
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

CVE-2025-59341
esm.sh General ⚡ nuclei
7.7
HIGH
EPSS
1.5%
2025 CWE-23 0 PoCs

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources).

CVE-2023-1974
answerdev/answer General
7.7
HIGH
EPSS
0.4%
2023 CWE-1230 1 PoC

Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.

CVE-2020-15256
object-path General
7.7
HIGH
EPSS
0.2%
2020 CWE-471 1 PoC

A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a wo

CVE-2023-30643
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2023 1 PoC

Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.

CVE-2024-8698
Software Genérico General ⚡ nuclei
7.7
HIGH
EPSS
81.3%
2024 CWE-347 1 PoC

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

CVE-2026-31851
Nebula 300+ General
7.7
HIGH
EPSS
0.1%
2026 CWE-307 1 PoC

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.

CVE-2026-32606
incus-os General
7.7
HIGH
EPSS
0.0%
2026 CWE-522 1 PoC

IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the system's owner or any tampering of Secure Boot state or kernel (UKI) boot image. That's because in this configuration, the LUKS key is made available by the TPM so long as the system has the expected PCR7 value and the PCR11 policy matches. That default PCR11 policy importantly allows for the TPM to rele

CVE-2026-34222
open-webui General
7.7
HIGH
EPSS
0.0%
2026 CWE-285 1 PoC

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.