40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-37478
pnpm General
7.5
HIGH
EPSS
1.6%
2023 CWE-284 2 PoCs

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVE-2021-23727
celery General
7.5
HIGH
EPSS
1.4%
2021 1 PoC

This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.

CVE-2021-23772
github.com/kataras/iris General
7.5
HIGH
EPSS
0.9%
2021 2 PoCs

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

CVE-2023-6042
Getwid General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Any unauthenticated user may send e-mail from the site with any title or content to the admin

CVE-2025-49182
SICK Media Server General
7.5
HIGH
EPSS
0.5%
2025 CWE-540 1 PoC

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

CVE-2024-25253
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

CVE-2023-34398
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.

CVE-2020-28496
three General
7.5
HIGH
EPSS
1.4%
2020 2 PoCs

This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blank (n) { var ret = "rgb(" for (var i = 0; i < n; i++) { ret += " " } return ret + ""; } var Color = three.Color var time = Date.now(); new Color(build_blank(50000)) var time_cost = Date.now() - time; console.log(time_cost+" ms")

CVE-2023-1444
Twister Antivirus General
7.5
HIGH
EPSS
0.6%
2023 CWE-404 1 PoC

A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223289 was assigned to this vulnerability.

CVE-2021-26406
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
7.5
HIGH
EPSS
0.2%
2021 2 PoCs

Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.

CVE-2024-4227
gSOAP General
7.5
HIGH
EPSS
0.2%
2024 CWE-834 1 PoC

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

CVE-2024-34659
Group Sharing General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

CVE-2025-63800
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

CVE-2024-44375
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

CVE-2024-42011
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

CVE-2022-47717
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).

CVE-2018-12408
TIBCO ActiveMatrix BusinessWorks General
7.5
HIGH
EPSS
0.3%
2018 1 PoC

The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks for z/Linux: versions up to and including 5.13.0, T

CVE-2022-1767
jgraph/drawio General
7.5
HIGH
EPSS
0.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

CVE-2023-20524
2nd Gen AMD EPYC™ General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

CVE-2025-30073
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions with the same reference are completed, depending on timing. This can be used to transfer more money onto employee cards than is paid.