40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2018-21100
Software Genérico General
7.6
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

CVE-2025-25616
Software Genérico General
7.6
HIGH
EPSS
0.6%
2025 1 PoC

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

CVE-2019-12266
Cam Pan v2 General
7.6
HIGH
EPSS
0.6%
2019 CWE-121 1 PoC

Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.49.1.47. Wyze Cam v2 versions prior to 4.9.8.1002. Wyze Cam v3 versions prior to 4.36.8.32.

CVE-2021-33601
F-Secure Internet Gatekeeper General
7.6
HIGH
EPSS
0.7%
2021 1 PoC

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

CVE-2021-3555
Indoor 2K Indoor Camera General
7.6
HIGH
EPSS
0.3%
2021 CWE-120 1 PoC

A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.

CVE-2019-9506
BR/EDR General
7.6
HIGH
EPSS
4.5%
2019 CWE-310 2 PoCs

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

CVE-2022-2472
CS-C6N-A0-1C2WFR General
7.6
HIGH
EPSS
0.2%
2022 CWE-665 1 PoC

Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428.

CVE-2020-4510
QRadar SIEM General
7.6
HIGH
EPSS
0.2%
2020 1 PoC

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182365.

CVE-2019-20761
Software Genérico General
7.6
HIGH
EPSS
0.3%
2019 1 PoC

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

CVE-2022-1021
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.3%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.

CVE-2022-37317
Software Genérico General
7.6
HIGH
EPSS
0.2%
2022 1 PoC

Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2022-1728
polonel/trudesk General
7.6
HIGH
EPSS
0.4%
2022 CWE-190 1 PoC

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVE-2022-2982
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0260.

CVE-2020-7304
DLP ePO extension General
7.6
HIGH
EPSS
0.1%
2020 CWE-352 1 PoC

Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.

CVE-2025-24095
iOS and iPadOS General
7.6
HIGH
EPSS
0.0%
2025 1 PoC

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.

CVE-2024-21689
Bamboo Data Center General
7.6
HIGH
EPSS
37.7%
2024 3 PoCs

This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one

CVE-2025-1933
Firefox General
7.6
HIGH
EPSS
0.5%
2025 1 PoC

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability was fixed in Firefox 136, Firefox ESR 115.21, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

CVE-2022-2862
vim/vim General
7.6
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0221.

CVE-2024-36443
Software Genérico General
7.6
HIGH
EPSS
0.5%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.