40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-30063
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

CVE-2024-23985
Software Genérico General
7.5
HIGH
EPSS
32.8%
2024 1 PoC

EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.

CVE-2024-48139
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2025-44044
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.

CVE-2024-51163
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print label function. Specifically, the filePathList parameter is susceptible to LFI, enabling a malicious user to include files from the web server, such as web.config or /etc/host, leading to the disclosure of sensitive information.

CVE-2024-21505
web3-utils General
7.5
HIGH
EPSS
0.1%
2024 CWE-1321 1 PoC

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

CVE-2025-54334
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function.

CVE-2025-47445
Eventin General ⚡ nuclei
7.5
HIGH
EPSS
8.8%
2025 CWE-23 0 PoCs

Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26.

CVE-2020-7668
github.com/unknwon/cae/tz General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

CVE-2024-24792
golang.org/x/image/tiff General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

CVE-2024-49196
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.

CVE-2024-21523
images General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

CVE-2025-34093
HDX Series General
7.5
HIGH
EPSS
69.4%
2025 CWE-78 1 PoC

An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute command in the devcmds console accepts unsanitized input, allowing attackers to execute arbitrary system commands. By injecting shell metacharacters through the traceroute interface, an attacker can achieve remote code execution under the context of the root user. This flaw affects systems where Telnet access is enabled and either unauthenticated access is allowed or credentials are known.

CVE-2024-49757
zitadel General ⚡ nuclei
7.5
HIGH
EPSS
10.8%
2024 CWE-287 0 PoCs

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

CVE-2022-0391
python General
7.5
HIGH
EPSS
1.2%
2022 CWE-74 1 PoC

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVE-2020-7771
asciitable.js General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

CVE-2025-3194
bigint-buffer General
7.5
HIGH
EPSS
0.4%
2025 CWE-120 1 PoC

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

CVE-2024-25734
Software Genérico General
7.5
HIGH
EPSS
6.3%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

CVE-2017-2810
Tablib General
7.5
HIGH
EPSS
1.4%
2017 1 PoC

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVE-2024-48140
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.