40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2012-0039
Software Genérico General
7.5
HIGH
EPSS
0.5%
2012 1 PoC

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

CVE-2023-6042
Getwid General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Any unauthenticated user may send e-mail from the site with any title or content to the admin

CVE-2024-34659
Group Sharing General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

CVE-2024-4227
gSOAP General
7.5
HIGH
EPSS
0.2%
2024 CWE-834 1 PoC

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

CVE-2022-48164
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
87.1%
2022 1 PoC

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2023-34398
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.

CVE-2021-28248
Software Genérico General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2024-42011
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

CVE-2025-61106
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2023-1444
Twister Antivirus General
7.5
HIGH
EPSS
0.6%
2023 CWE-404 1 PoC

A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223289 was assigned to this vulnerability.

CVE-2024-44375
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

CVE-2023-20524
2nd Gen AMD EPYC™ General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

CVE-2021-34581
750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 General
7.5
HIGH
EPSS
1.7%
2021 CWE-772 1 PoC

Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.

CVE-2024-33605
Multiple MFPs (multifunction printers) General ⚡ nuclei
7.5
HIGH
EPSS
60.2%
2024 CWE-22 3 PoCs

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2021-32568
zmister2016/mrdoc General
7.5
HIGH
EPSS
0.3%
2021 CWE-502 1 PoC

mrdoc is vulnerable to Deserialization of Untrusted Data

CVE-2025-67133
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

CVE-2024-28716
Software Genérico General
7.5
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVE-2024-49193
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.

CVE-2023-31300
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

CVE-2022-42893
syngo Dynamics General
7.5
HIGH
EPSS
0.2%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.