40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-24792
golang.org/x/image/tiff General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

CVE-2022-21935
Metasys ADS/ADX/OAS server General
7.5
HIGH
EPSS
0.2%
2022 CWE-620 1 PoC

A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

CVE-2020-8975
ZGR TPS200 NG General
7.5
HIGH
EPSS
0.2%
2020 CWE-201 1 PoC

ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access sensitive information about the system.

CVE-2024-51163
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print label function. Specifically, the filePathList parameter is susceptible to LFI, enabling a malicious user to include files from the web server, such as web.config or /etc/host, leading to the disclosure of sensitive information.

CVE-2020-8617
BIND9 General
7.5
HIGH
EPSS
92.6%
2020 5 PoCs

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an i

CVE-2020-28442
js-data General
7.5
HIGH
EPSS
0.6%
2020 3 PoCs

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

CVE-2025-22387
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 CWE-598 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVE-2024-49196
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.

CVE-2024-21523
images General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

CVE-2023-29298
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CVE-2024-49757
zitadel General ⚡ nuclei
7.5
HIGH
EPSS
10.8%
2024 CWE-287 0 PoCs

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

CVE-2024-47922
PRI WEB General
7.5
HIGH
EPSS
0.1%
2024 CWE-200 1 PoC

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-40786
iOS and iPadOS General
7.5
HIGH
EPSS
0.2%
2024 3 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.

CVE-2024-48140
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-25734
Software Genérico General
7.5
HIGH
EPSS
6.3%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

CVE-2021-3807
chalk/ansi-regex General
7.5
HIGH
EPSS
0.2%
2021 CWE-1333 2 PoCs

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVE-2022-42125
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.

CVE-2020-6077
Videolabs General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

CVE-2022-2004
DirectLOGIC D0-06 series CPUs General
7.5
HIGH
EPSS
0.1%
2022 CWE-400 1 PoC

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and other devices, causing a denial-of-service condition. This issue affects: AutomationDirect DirectLOGIC D0-06 series CPUs D0-06DD1 versions prior to 2.72; D0-06DD2 versions prior to 2.72; D0-06DR versions prior to 2.72; D0-06DA versions prior to 2.72; D0-06AR versions prior to 2.72; D0-06AA versions prior to 2.72; D0-06DD1-D versions prior to 2.72; D0-06DD2-D versions prior to 2.72; D0-06DR-D versions prior to 2.72;