40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2192
HYPR Server General
7.5
HIGH
EPSS
0.7%
2022 CWE-425 1 PoC

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

CVE-2020-26868
PcVue General
7.5
HIGH
EPSS
1.1%
2020 CWE-767 2 PoCs

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.

CVE-2019-0752
🔥 KEV Internet Explorer 11 General
7.5
HIGH
EPSS
91.8%
2019 3 PoCs

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.

CVE-2019-5038
Nest Labs General
7.5
HIGH
EPSS
1.1%
2019 CWE-121 1 PoC

An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.

CVE-2019-8394
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
87.5%
2019 1 PoC

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

CVE-2019-16638
Software Genérico General
7.5
HIGH
EPSS
0.1%
2019 1 PoC

An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects EG-2000SE EG_RGOS 11.1(1)B1.

CVE-2019-25053
Software Genérico General
7.5
HIGH
EPSS
0.8%
2019 1 PoC

A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attackers to access files outside of the web tree via a crafted URL.

CVE-2025-11678
libwebsocket General
7.5
HIGH
EPSS
0.0%
2025 CWE-121 1 PoC

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

CVE-2018-17559
Software Genérico General
7.5
HIGH
EPSS
0.2%
2018 1 PoC

Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.

CVE-2020-6196
SAP BusinessObjects Mobile (MobileBIService) General
7.5
HIGH
EPSS
0.5%
2020 1 PoC

SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads resulting in a Denial of Service.

CVE-2021-22222
Wireshark General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file

CVE-2019-9621
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2019 4 PoCs

Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

CVE-2019-20690
Software Genérico General
7.5
HIGH
EPSS
0.1%
2019 1 PoC

Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.30, D7000 before 1.0.1.66, R6020 before 1.0.0.34, R6080 before 1.0.0.34, R6120 before 1.0.0.44, R6220 before 1.1.0.68, WNR2020 before 1.1.0.54, and WNR614 before 1.1.0.54.

CVE-2019-5039
Nest Labs General
7.5
HIGH
EPSS
0.7%
2019 CWE-122 1 PoC

An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

CVE-2025-27594
SICK DL100-2xxxxxxx General
7.5
HIGH
EPSS
0.1%
2025 CWE-319 1 PoC

The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a pass-the-hash attack.

CVE-2019-14892
jackson-databind General
7.5
HIGH
EPSS
0.9%
2019 CWE-502 1 PoC

A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

CVE-2019-16673
Software Genérico General
7.5
HIGH
EPSS
0.3%
2019 2 PoCs

An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.

CVE-2024-50609
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 1 PoC

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to

CVE-2025-60536
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file.

CVE-2024-33383
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.