40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-33818
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

CVE-2022-40899
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

CVE-2025-28235
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.

CVE-2024-24430
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-23911
Cente IPv6 General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.

CVE-2024-41335
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to utilize insecure versions of the functions strcmp and memcmp, allowing attackers to possibly obtain sensitive information via timing attacks.

CVE-2024-20137
MT6890, MT7622, MT7915, MT7916, MT7981, MT7986 General
7.5
HIGH
EPSS
10.1%
2024 CWE-248 1 PoC

In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.

CVE-2020-12516
750-331/xxx-xxx General
7.5
HIGH
EPSS
0.4%
2020 CWE-400 2 PoCs

Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

CVE-2024-39614
Software Genérico General
7.5
HIGH
EPSS
6.8%
2024 1 PoC

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.

CVE-2024-51739
iTop General ⚡ nuclei
7.5
HIGH
EPSS
31.6%
2024 CWE-200 0 PoCs

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. Users unable to upgrade may overload the dictionary entry `"UI:ResetPwd-Error-WrongLogin"` through an extension and replace it with a generic message.

CVE-2020-7768
grpc General
7.5
HIGH
EPSS
1.3%
2020 4 PoCs

The package grpc before 1.24.4; the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.

CVE-2024-55008
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.

CVE-2021-46755
Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVE-2024-34587
Samsung Mobile Devices General
7.5
HIGH
EPSS
1.0%
2024 1 PoC

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-5803
Antivirus General
7.5
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.

CVE-2017-14460
Parity General
7.5
HIGH
EPSS
0.5%
2017 1 PoC

An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatically sent JSON object to JSON-RPC endpoint can trigger this vulnerability. A victim needs to visit a malicious website to trigger this vulnerability.

CVE-2024-2886
Chrome General
7.5
HIGH
EPSS
1.5%
2024 1 PoC

Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVE-2024-40675
Android General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-55569
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2024-29384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.