40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-20530
3rd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.

CVE-2024-4558
Chrome General
7.5
HIGH
EPSS
2.4%
2024 4 PoCs

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-6293
robinbuschmann/sequelize-typescript General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6.

CVE-2023-28770
DX5401-B0 firmware General
7.5
HIGH
EPSS
83.7%
2023 CWE-200 1 PoC

The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior to V5.17(ABYO.1)C0 could allow a remote unauthenticated attacker to read the system files and to retrieve the password of the supervisor from the encrypted file.

CVE-2024-27821
iOS and iPadOS General
7.5
HIGH
EPSS
2.4%
2024 1 PoC

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.

CVE-2025-58180
OctoPrint General
7.5
HIGH
EPSS
1.6%
2025 CWE-78 1 PoC

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered. If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact. The vulnerability is patched in version 1.11.3. As a work

CVE-2021-1938
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2024-34351
next.js General ⚡ nuclei
7.5
HIGH
EPSS
92.8%
2024 CWE-918 3 PoCs

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vuln

CVE-2021-30329
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2022-25882
onnx General
7.5
HIGH
EPSS
5.8%
2022 CWE-22 1 PoC

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

CVE-2024-8232
SpiderControl SCADA Web Server General
7.5
HIGH
EPSS
4.5%
2024 CWE-434 1 PoC

SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

CVE-2020-6083
Allen Bradley General
7.5
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-31904
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 1 PoC

savysoda Wifi HD Wireless Disk Drive 11 is vulnerable to Local File Inclusion.

CVE-2023-24472
OpenImageIO General
7.5
HIGH
EPSS
0.1%
2023 CWE-674 1 PoC

A denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide malicious input to trigger this vulnerability.

CVE-2024-27318
onnx General
7.5
HIGH
EPSS
0.3%
2024 CWE-22 1 PoC

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.

CVE-2024-24431
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

CVE-2021-3801
prismjs/prism General
7.5
HIGH
EPSS
0.3%
2021 CWE-1333 1 PoC

prism is vulnerable to Inefficient Regular Expression Complexity

CVE-2023-28509
UniData General
7.5
HIGH
EPSS
0.1%
2023 CWE-327 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.

CVE-2024-11318
AbsysNet General
7.5
HIGH
EPSS
26.7%
2024 CWE-639 1 PoC

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking the session identifier on the "/cgi-bin/ocap/" endpoint.

CVE-2024-47214
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.