40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-42860
macOS General
7.7
HIGH
EPSS
0.4%
2023 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.

CVE-2026-34222
open-webui General
7.7
HIGH
EPSS
0.0%
2026 CWE-285 1 PoC

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.

CVE-2021-34378
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial of service, or escalation of privileges.

CVE-2021-21953
Anker General
7.7
HIGH
EPSS
0.3%
2021 CWE-300 1 PoC

An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.

CVE-2021-34374
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

CVE-2021-21959
Sealevel General
7.7
HIGH
EPSS
0.3%
2021 CWE-295 1 PoC

A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.

CVE-2024-8040
3DSwymer General
7.7
HIGH
EPSS
0.0%
2024 CWE-639 1 PoC

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

CVE-2022-50976
VibroLine Configurator 5.0 General
7.7
HIGH
EPSS
0.0%
2022 CWE-1288 2 PoCs

A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

CVE-2022-22264
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.

CVE-2023-6570
kubeflow/kubeflow General
7.7
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

CVE-2021-4171
janeczku/calibre-web General
7.7
HIGH
EPSS
0.4%
2021 CWE-840 1 PoC

calibre-web is vulnerable to Business Logic Errors

CVE-2024-56429
iLabClient General
7.7
HIGH
EPSS
0.1%
2024 CWE-321 1 PoC

itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

CVE-2017-12090
Allen Bradley General
7.7
HIGH
EPSS
0.0%
2017 1 PoC

An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flashing snmp-set commands, can cause a device power cycle resulting in downtime for the device. An attacker can send one packet to trigger this vulnerability.

CVE-2020-15256
object-path General
7.7
HIGH
EPSS
0.2%
2020 CWE-471 1 PoC

A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a wo

CVE-2024-38449
Software Genérico General
7.7
HIGH
EPSS
0.2%
2024 1 PoC

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.

CVE-2022-0895
microweber/microweber General
7.7
HIGH
EPSS
1.2%
2022 CWE-96 1 PoC

Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

CVE-2024-40824
iOS and iPadOS General
7.7
HIGH
EPSS
0.0%
2024 2 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2022-3570
libtiff General
7.7
HIGH
EPSS
0.0%
2022 2 PoCs

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact

CVE-2025-59341
esm.sh General ⚡ nuclei
7.7
HIGH
EPSS
1.5%
2025 CWE-23 0 PoCs

esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host filesystem (or other unintended file sources).

CVE-2022-35978
minetest General
7.7
HIGH
EPSS
13.7%
2022 CWE-693 1 PoC

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.