40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48141
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2020-26243
nanopb General
7.5
HIGH
EPSS
0.1%
2020 CWE-20 1 PoC

Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static submessage that contains a dynamic field, and the message being decoded contains the submessage multiple times. This is rare in normal messages, but it is a concern when untrusted data is parsed. This is fixed in versions 0.3.9.7 and 0.4.4. The following workarounds are available: 1) Set the option `no_unions` for the oneof field. This will generate fields as separate

CVE-2025-27685
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.

CVE-2024-23261
macOS General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVE-2021-46749
Ryzen™ 2000 Series Desktop Processors “Pinnacle Ridge” General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

CVE-2020-26869
PcVue General
7.5
HIGH
EPSS
0.5%
2020 CWE-200 1 PoC

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.

CVE-2023-39539
AptioV General
7.5
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

CVE-2024-47187
suricata General
7.5
HIGH
EPSS
0.1%
2024 CWE-330 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

CVE-2022-31474
BackupBuddy General ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2022 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

CVE-2023-25260
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2017-3143
BIND 9 General
7.5
HIGH
EPSS
26.9%
2017 1 PoC

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

CVE-2024-33530
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

CVE-2022-2321
heroiclabs/nakama General
7.5
HIGH
EPSS
0.3%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

CVE-2024-53473
Software Genérico General
7.5
HIGH
EPSS
0.9%
2024 2 PoCs

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

CVE-2025-65513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

fetch-mcp v1.0.2 and before is vulnerable to Server-Side Request Forgery (SSRF) vulnerability, which allows attackers to bypass private IP validation and access internal network resources.

CVE-2022-26043
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2024-46938
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2024 0 PoCs

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

CVE-2022-25852
pg-native General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.

CVE-2024-34666
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-25164
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.