40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3777
daaku/nodejs-tmpl General
7.5
HIGH
EPSS
0.4%
2021 CWE-1333 1 PoC

nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-30301
Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2022-4636
KVM ACR1020A-T General
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

CVE-2020-7755
dat.gui General
7.5
HIGH
EPSS
0.6%
2020 1 PoC

All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values.

CVE-2024-49193
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.

CVE-2024-55196
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

CVE-2023-22435
Experion Server General
7.5
HIGH
EPSS
0.1%
2023 CWE-697 1 PoC

Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

CVE-2024-28716
Software Genérico General
7.5
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVE-2025-34093
HDX Series General
7.5
HIGH
EPSS
69.4%
2025 CWE-78 1 PoC

An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute command in the devcmds console accepts unsanitized input, allowing attackers to execute arbitrary system commands. By injecting shell metacharacters through the traceroute interface, an attacker can achieve remote code execution under the context of the root user. This flaw affects systems where Telnet access is enabled and either unauthenticated access is allowed or credentials are known.

CVE-2024-55568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVE-2014-0160
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
94.5%
2014 34 PoCs

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

CVE-2020-6208
SAP Business Objects Business Intelligence Platform (Crystal Reports) General
7.5
HIGH
EPSS
2.6%
2020 1 PoC

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.

CVE-2025-41703
QUINT4-UPS/24DC/24DC/5/EIP General
7.5
HIGH
EPSS
0.2%
2025 CWE-306 1 PoC

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

CVE-2021-30304
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity

CVE-2020-11274
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2020 1 PoC

Denial of service in MODEM due to assert to the invalid configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2025-43706
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920, W930, Modem 5123, and Modem 5400. Incorrect handling of RRC packets leads to a Denial of Service.

CVE-2023-34092
vite General ⚡ nuclei
7.5
HIGH
EPSS
44.8%
2023 CWE-50 1 PoC

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3

CVE-2024-12085
Software Genérico General
7.5
HIGH
EPSS
19.1%
2024 CWE-908 1 PoC

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVE-2024-32825
Simply Static General ⚡ nuclei
7.5
HIGH
EPSS
25.8%
2024 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.

CVE-2024-22641
Software Genérico General
7.5
HIGH
EPSS
9.0%
2024 1 PoC

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.