40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-39033
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

CVE-2022-40898
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVE-2024-40803
macOS General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An attacker may be able to cause unexpected app termination.

CVE-2025-60751
Software Genérico General
7.5
HIGH
EPSS
0.6%
2025 1 PoC

GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

CVE-2025-27225
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
21.7%
2025 1 PoC

TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.

CVE-2021-3805
mariocasciaro/object-path General
7.5
HIGH
EPSS
0.7%
2021 CWE-1321 1 PoC

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2025-2284
Sante PACS Server General
7.5
HIGH
EPSS
6.8%
2025 CWE-824 1 PoC

A denial-of-service vulnerability exists in the "GetWebLoginCredentials" function in "Sante PACS Server.exe".

CVE-2024-31392
Firefox for iOS General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVE-2024-6291
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-25936
servst General
7.5
HIGH
EPSS
1.6%
2022 CWE-22 1 PoC

Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable.

CVE-2024-40815
iOS and iPadOS General
7.5
HIGH
EPSS
7.2%
2024 4 PoCs

A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

CVE-2020-29500
PowerStore General
7.5
HIGH
EPSS
0.0%
2020 CWE-312 1 PoC

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

CVE-2024-47213
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.

CVE-2021-3998
glibc General
7.5
HIGH
EPSS
0.2%
2021 CWE-125 1 PoC

A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.

CVE-2024-34668
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2025-55780
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.

CVE-2024-33818
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

CVE-2020-11255
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables

CVE-2024-48125
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol requests.

CVE-2017-2807
Ledger CLI General
7.5
HIGH
EPSS
0.6%
2017 1 PoC

An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.