40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-11273
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null pointer access when histogram binning info is missing due to lack of null check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVE-2021-22286
SPIET800 General
7.5
HIGH
EPSS
0.5%
2021 CWE-20 1 PoC

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

CVE-2021-46755
Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVE-2023-26976
Software Genérico General
7.5
HIGH
EPSS
18.6%
2023 1 PoC

Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

CVE-2018-3852
Ocularis General
7.5
HIGH
EPSS
0.6%
2018 1 PoC

An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet can cause a process to terminate resulting in denial of service. An attacker can send a crafted TCP packet to trigger this vulnerability.

CVE-2024-35431
Software Genérico General
7.5
HIGH
EPSS
3.0%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.

CVE-2023-28809
DS-K1T804AXX General
7.5
HIGH
EPSS
0.2%
2023 CWE-284 1 PoC

Some access control products are vulnerable to a session hijacking attack because the product does not update the session ID after a user successfully logs in. To exploit the vulnerability, attackers have to request the session ID at the same time as a valid user logs in, and gain device operation permissions by forging the IP and session ID of an authenticated user.

CVE-2024-40829
iOS and iPadOS General
7.5
HIGH
EPSS
0.4%
2024 3 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.

CVE-2025-69260
Trend Micro Apex Central General
7.5
HIGH
EPSS
0.5%
2025 CWE-346 1 PoC

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

CVE-2023-26139
underscore-keypath General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.

CVE-2020-4206
Spectrum Protect Plus General
7.5
HIGH
EPSS
2.7%
2020 1 PoC

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.

CVE-2023-25368
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can overwrite firmnware.

CVE-2024-34619
Samsung Mobile Devices General
7.5
HIGH
EPSS
1.5%
2024 1 PoC

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2025-65287
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.

CVE-2023-21444
Samsung Flow for PC General
7.5
HIGH
EPSS
0.1%
2023 CWE-326 1 PoC

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVE-2025-26785
Software Genérico General
7.5
HIGH
EPSS
0.4%
2025 2 PoCs

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2024-28806
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

CVE-2022-2321
heroiclabs/nakama General
7.5
HIGH
EPSS
0.3%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

CVE-2014-2364
WebAccess General
7.5
UNKNOWN
EPSS
40.2%
2014 CWE-121 1 PoC

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

CVE-2023-43768
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 2 PoCs

An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.