40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-25260
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2024-23261
macOS General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVE-2022-24298
FreeOpcUa/freeopcua General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2025-32470
SICK FLX0-GPNT100 General
7.5
HIGH
EPSS
0.7%
2025 CWE-284 1 PoC

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

CVE-2022-3371
ikus060/rdiffweb General
7.5
HIGH
EPSS
0.5%
2022 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

CVE-2020-7772
doc-path General
7.5
HIGH
EPSS
0.8%
2020 1 PoC

This affects the package doc-path before 2.1.2.

CVE-2021-35065
Software Genérico General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

CVE-2024-47187
suricata General
7.5
HIGH
EPSS
0.1%
2024 CWE-330 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

CVE-2025-59375
libexpat General
7.5
HIGH
EPSS
0.1%
2025 CWE-770 1 PoC

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

CVE-2022-42734
syngo Dynamics General
7.5
HIGH
EPSS
0.2%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.

CVE-2020-6080
Videolabs General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through the function rr_read_RR [5] reads the current resource record, except for the RDATA section. This is read by the loop at in rr_read. For each RR type, a different function is called. When the RR type is 0x10, the function rr_rea

CVE-2024-33530
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

CVE-2018-11058
BSAFE Micro Edition Suite General
7.5
HIGH
EPSS
1.6%
2018 5 PoCs

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

CVE-2022-4450
OpenSSL General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a buffer that has already been freed. If the ca

CVE-2022-21144
libxmljs General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.

CVE-2024-53473
Software Genérico General
7.5
HIGH
EPSS
0.9%
2024 2 PoCs

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

CVE-2024-56527
tcpdf General
7.5
HIGH
EPSS
0.5%
2024 CWE-79 1 PoC

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

CVE-2024-46938
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2024 0 PoCs

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

CVE-2018-10920
knot-resolver General
7.5
HIGH
EPSS
12.2%
2018 CWE-20 1 PoC

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

CVE-2024-34666
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.