40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-36512
Comdb2 General
7.5
HIGH
EPSS
0.1%
2025 CWE-617 2 PoCs

A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.

CVE-2024-53473
Software Genérico General
7.5
HIGH
EPSS
0.9%
2024 2 PoCs

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

CVE-2021-3805
mariocasciaro/object-path General
7.5
HIGH
EPSS
0.7%
2021 CWE-1321 1 PoC

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2024-34666
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-25164
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

CVE-2024-34669
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2023-49298
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in t

CVE-2022-36537
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.9%
2022 4 PoCs

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CVE-2024-46938
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2024 0 PoCs

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

CVE-2024-33530
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

CVE-2024-51982
HL-L8260CDN General
7.5
HIGH
EPSS
1.1%
2024 CWE-1286 2 PoCs

An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device. A malformed PJL variable FORMLINES is set to a non number value causing the target to crash.

CVE-2024-57716
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

CVE-2023-37608
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.

CVE-2024-28442
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.

CVE-2020-37011
Fonts Viewer General
7.5
HIGH
EPSS
0.0%
2020 CWE-787 1 PoC

Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to cause an infinite malloc() loop and potentially crash the gnome-font-viewer process.

CVE-2024-49420
GamingHub General
7.5
HIGH
EPSS
1.4%
2024 1 PoC

Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.

CVE-2020-7763
phantom-html-to-pdf General
7.5
HIGH
EPSS
0.4%
2020 2 PoCs

This affects the package phantom-html-to-pdf before 0.6.1.

CVE-2023-26111
@nubosoftware/node-static General
7.5
HIGH
EPSS
1.3%
2023 CWE-22 2 PoCs

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

CVE-2020-4269
Qradar General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.

CVE-2025-60349
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated.