40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-59460
TLOC100-100 with Firmware <7.1.1 General
7.5
HIGH
EPSS
0.1%
2025 CWE-1391 1 PoC

The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.

CVE-2024-53522
Software Genérico General
7.5
HIGH
EPSS
1.0%
2024 2 PoCs

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

CVE-2024-25458
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a crafted request to a UDP port.

CVE-2024-46923
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_ib_fill in the Xclipse Driver.

CVE-2024-56426
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000. The lack of a length check leads to out-of-bounds writes via malformed USB packets to the target.

CVE-2024-48645
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server.

CVE-2024-29059
🔥 KEV Microsoft .NET Framework 4.8 General ⚡ nuclei
7.5
HIGH
EPSS
93.7%
2024 CWE-209 0 PoCs

.NET Framework Information Disclosure Vulnerability

CVE-2020-13530
EIP Stack Group General
7.5
HIGH
EPSS
0.4%
2020 CWE-910 1 PoC

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2024-53621
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-30571
Software Genérico General
7.5
HIGH
EPSS
22.0%
2024 1 PoC

An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-23302
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 2 PoCs

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

CVE-2024-21907
Software Genérico General
7.5
HIGH
EPSS
2.9%
2024 CWE-755 2 PoCs

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

CVE-2024-26331
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
67.9%
2024 0 PoCs

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.

CVE-2020-28442
js-data General
7.5
HIGH
EPSS
0.6%
2020 3 PoCs

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

CVE-2025-26780
Software Genérico General
7.5
HIGH
EPSS
0.5%
2025 2 PoCs

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.

CVE-2024-50600
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access. An attacker can send a malformed message to the target through the Wi-Fi driver.

CVE-2021-30310
Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2024-7409
Software Genérico General
7.5
HIGH
EPSS
1.7%
2024 CWE-662 1 PoC

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

CVE-2021-46764
2nd Gen AMD EPYC™ General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.

CVE-2021-23359
port-killer General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.