40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-11243
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

RRC sends a connection establishment success to NAS even though connection setup validation returns failure and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVE-2025-46709
Graphics DDK General
7.5
HIGH
EPSS
0.1%
2025 CWE-416 1 PoC

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

CVE-2026-1584
Red Hat Hardened Images General
7.5
HIGH
EPSS
0.1%
2026 CWE-476 1 PoC

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.

CVE-2024-41696
PRI WEB Portal Add-On for Priority ERP on prem General
7.5
HIGH
EPSS
0.4%
2024 CWE-200 1 PoC

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2026-30999
Software Genérico General
7.5
HIGH
EPSS
0.1%
2026 1 PoC

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-23766
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.

CVE-2022-38870
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2022 0 PoCs

Free5gc v3.2.1 is vulnerable to Information disclosure.

CVE-2021-30330
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible null pointer dereference due to improper validation of APE clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2026-4602
jsrsasign General
7.5
HIGH
EPSS
0.1%
2026 CWE-681 1 PoC

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

CVE-2026-29858
Software Genérico General
7.5
HIGH
EPSS
0.1%
2026 1 PoC

A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure.

CVE-2026-30998
Software Genérico General
7.5
HIGH
EPSS
0.0%
2026 1 PoC

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

CVE-2021-20997
0852-0303 General
7.5
HIGH
EPSS
0.3%
2021 CWE-522 1 PoC

In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

CVE-2021-28248
Software Genérico General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2022-25885
muhammara General
7.5
HIGH
EPSS
0.9%
2022 2 PoCs

The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.

CVE-2024-45432
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain sensitive information.

CVE-2020-4979
QRadar SIEM General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.

CVE-2024-41695
PineApp Mail Relay General
7.5
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

CVE-2024-8751
SICK MSC800 General
7.5
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. Users are recommended to upgrade both MSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively which fixes this issue.

CVE-2024-41996
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 3 PoCs

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.

CVE-2021-3649
chatwoot/chatwoot General
7.5
HIGH
EPSS
0.3%
2021 CWE-1333 1 PoC

chatwoot is vulnerable to Inefficient Regular Expression Complexity