40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-4316
Zod General
7.5
HIGH
EPSS
0.1%
2023 CWE-1333 1 PoC

Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

CVE-2021-3810
cdr/code-server General
7.5
HIGH
EPSS
0.2%
2021 CWE-1333 1 PoC

code-server is vulnerable to Inefficient Regular Expression Complexity

CVE-2024-31846
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2024-23660
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

CVE-2021-27597
SAP NetWeaver AS for ABAP (RFC Gateway) General
7.5
HIGH
EPSS
0.3%
2021 CWE-125 2 PoCs

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method memmove() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2023-49355
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

CVE-2024-55272
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

CVE-2023-30285
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.

CVE-2020-6097
atftpd General
7.5
HIGH
EPSS
0.3%
2020 CWE-617 1 PoC

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVE-2023-45131
discourse General
7.5
HIGH
EPSS
7.4%
2023 CWE-200 1 PoC

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-41404
Software Genérico General
7.5
HIGH
EPSS
0.8%
2022 2 PoCs

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVE-2023-30861
flask General
7.5
HIGH
EPSS
0.2%
2023 CWE-539 2 PoCs

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client's `session` cookie to other clients. The severity depends on the application's use of the session and the proxy's behavior regarding cookies. The risk depends on all these conditions being met. 1. The application must be hosted behind a caching proxy that does not strip cookies or ignore responses with cookie

CVE-2024-0760
BIND 9 General
7.5
HIGH
EPSS
16.7%
2024 1 PoC

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

CVE-2022-44356
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
47.1%
2022 0 PoCs

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

CVE-2024-46471
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

CVE-2022-37255
Software Genérico General
7.5
HIGH
EPSS
9.3%
2022 1 PoC

TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.

CVE-2025-9784
Software Genérico General
7.5
HIGH
EPSS
1.7%
2025 CWE-770 1 PoC

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CVE-2021-26419
Internet Explorer 11 General
7.5
HIGH
EPSS
34.1%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2024-52884
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.