40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-32503
Software Genérico General
7.6
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.

CVE-2022-27835
Samsung Mobile Devices General
7.6
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVE-2022-34453
XtremIO X2 General
7.6
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled by default.

CVE-2021-3555
Indoor 2K Indoor Camera General
7.6
HIGH
EPSS
0.3%
2021 CWE-120 1 PoC

A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2018-6677
McAfee Web Gateway (MWG) General
7.6
HIGH
EPSS
0.5%
2018 1 PoC

Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors.

CVE-2023-26074
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding operator-defined access category definitions.

CVE-2022-2901
chatwoot/chatwoot General
7.6
HIGH
EPSS
0.1%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.

CVE-2023-5808
System Management Unit (SMU) General
7.6
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

CVE-2023-6538
System Management Unit (SMU) General
7.6
HIGH
EPSS
5.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

CVE-2018-21099
Software Genérico General
7.6
HIGH
EPSS
0.3%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

CVE-2025-9959
Software Genérico General
7.6
HIGH
EPSS
0.1%
2025 CWE-94 1 PoC

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

CVE-2023-4263
Zephyr General
7.6
HIGH
EPSS
0.1%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver

CVE-2023-0455
unilogies/bumsys General
7.6
HIGH
EPSS
5.6%
2023 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.

CVE-2020-26830
SAP Solution Manager (User Experience Monitoring) General
7.6
HIGH
EPSS
0.3%
2020 1 PoC

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience Monitoring configuration, obtain details about the configured SAP Solution Manager agents, Deploy a malicious User Experience Monitoring script.

CVE-2023-42571
Find My Mobile General
7.6
HIGH
EPSS
0.2%
2023 1 PoC

Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.

CVE-2023-4257
Zephyr General
7.6
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

CVE-2023-44092
Pandora FMS General
7.6
HIGH
EPSS
0.1%
2023 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.

CVE-2022-3721
froxlor/froxlor General
7.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

CVE-2025-30072
Software Genérico General
7.6
HIGH
EPSS
0.2%
2025 2 PoCs

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.