40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-34374
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

CVE-2020-15256
object-path General
7.7
HIGH
EPSS
0.2%
2020 CWE-471 1 PoC

A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a wo

CVE-2025-25293
ruby-saml General
7.7
HIGH
EPSS
6.2%
2025 CWE-400 1 PoC

ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress SAML responses in case they're compressed. It is possible to bypass the message size check with a compressed assertion since the message size is checked before inflation and not after. This issue may lead to remote Denial of Service (DoS). Versions 1.12.4 and 1.18.0 fix the issue.

CVE-2024-40805
iOS and iPadOS General
7.7
HIGH
EPSS
0.0%
2024 2 PoCs

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2025-32808
InQuizitive General
7.7
HIGH
EPSS
0.2%
2025 CWE-602 1 PoC

W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.

CVE-2025-4569
MyASUS General
7.7
HIGH
EPSS
0.1%
2025 CWE-798 1 PoC

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more information.

CVE-2021-4171
janeczku/calibre-web General
7.7
HIGH
EPSS
0.4%
2021 CWE-840 1 PoC

calibre-web is vulnerable to Business Logic Errors

CVE-2025-30076
Koha General
7.7
HIGH
EPSS
0.1%
2025 CWE-78 1 PoC

Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

CVE-2021-34375
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and information disclosure.

CVE-2023-22835
com.palantir.foundry:foundry-frontend General
7.7
HIGH
EPSS
0.4%
2023 CWE-20 1 PoC

A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend functionality to all issue participants. This defect was resolved with the release of Foundry Issues 2.510.0 and Foundry Frontend 6.228.0.

CVE-2021-34376
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to denial of service, escalation of privileges, and information disclosure.

CVE-2020-7254
McAfee Advanced Threat Defense (ATD) General
7.7
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

CVE-2023-30643
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2023 1 PoC

Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.

CVE-2023-2590
answerdev/answer General
7.7
HIGH
EPSS
0.1%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9.

CVE-2022-28781
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

CVE-2023-42860
macOS General
7.7
HIGH
EPSS
0.4%
2023 1 PoC

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to modify protected parts of the file system.

CVE-2021-34377
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, information disclosure, and denial of service.

CVE-2022-42275
NVIDIA DGX servers General
7.7
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

CVE-2023-49287
tinydir General
7.7
HIGH
EPSS
2.5%
2023 CWE-120 1 PoC

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.

CVE-2023-4435
hamza417/inure General
7.7
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository hamza417/inure prior to build88.