40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-4214
Spectrum Protect Plus General
7.5
HIGH
EPSS
0.7%
2020 1 PoC

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.

CVE-2020-18329
Software Genérico General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface.

CVE-2023-44829
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2020-36518
Software Genérico General
7.5
HIGH
EPSS
0.5%
2020 3 PoCs

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

CVE-2023-1580
Gateway General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.

CVE-2025-55780
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in a crash if the split fails or returns a partial node chain.

CVE-2016-9049
Database Server General
7.5
HIGH
EPSS
1.4%
2016 2 PoCs

An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process to dereference a null pointer. An attacker can simply connect to a TCP port in order to trigger this vulnerability.

CVE-2025-66960
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

CVE-2023-45854
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

CVE-2024-31841
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

CVE-2024-42651
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.

CVE-2024-8176
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 CWE-674 2 PoCs

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

CVE-2023-26152
static-server General
7.5
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

CVE-2025-51495
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.

CVE-2025-56223
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

CVE-2025-63219
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

CVE-2023-31115
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.

CVE-2023-29740
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database.

CVE-2023-5392
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-1295 1 PoC

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2024-36857
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
53.4%
2024 0 PoCs

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.