40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-23702
object-extend General
7.6
HIGH
EPSS
0.4%
2021 1 PoC

The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.

CVE-2026-29870
Software Genérico General
7.6
HIGH
EPSS
0.1%
2026 1 PoC

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the intended checkpoint directory. This vulnerability allows attackers to overwrite arbitrary files accessible to the application process, potentially leading to application corruption, privilege escalation, or code execution depending on the deployment context.

CVE-2024-42464
upKeeper Manager General
7.6
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.

CVE-2026-1007
Server General
7.6
HIGH
EPSS
0.0%
2026 CWE-863 1 PoC

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

CVE-2026-2476
Mattermost General
7.6
HIGH
EPSS
0.0%
2026 CWE-200 1 PoC

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606

CVE-2026-1046
Mattermost General
7.6
HIGH
EPSS
0.0%
2026 CWE-939 1 PoC

Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

CVE-2025-24095
iOS and iPadOS General
7.6
HIGH
EPSS
0.0%
2025 1 PoC

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.

CVE-2021-45595
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22.

CVE-2024-25652
Secret Server General
7.6
HIGH
EPSS
0.3%
2024 CWE-287 2 PoCs

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

CVE-2020-7304
DLP ePO extension General
7.6
HIGH
EPSS
0.1%
2020 CWE-352 1 PoC

Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.

CVE-2024-3841
Chrome General
7.6
HIGH
EPSS
0.4%
2024 1 PoC

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2023-3069
tsolucio/corebos General
7.6
HIGH
EPSS
0.1%
2023 CWE-620 1 PoC

Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

CVE-2024-32399
Software Genérico General ⚡ nuclei
7.6
HIGH
EPSS
83.5%
2024 2 PoCs

Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

CVE-2020-24898
Software Genérico General
7.6
HIGH
EPSS
0.2%
2020 1 PoC

The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).

CVE-2024-28247
pi-hole General
7.6
HIGH
EPSS
7.1%
2024 CWE-200 1 PoC

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files arbitrarily, and because the application runs from behind, reading files is done as a privileged user.If the URL that is in the list of "Adslists" begins with "file*" it is understood that it is updating from a local file, on the other hand if it does not begin with "file*" depending on the state of the response it does one thing or another. The pr

CVE-2018-6677
McAfee Web Gateway (MWG) General
7.6
HIGH
EPSS
0.5%
2018 1 PoC

Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors.

CVE-2023-22833
com.palantir.lime:lime2 General
7.6
HIGH
EPSS
0.1%
2023 CWE-304 1 PoC

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

CVE-2024-41630
Software Genérico General
7.6
HIGH
EPSS
2.5%
2024 1 PoC

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

CVE-2023-26072
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Emergency number list.