40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-6960
TTLock App General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

CVE-2023-20531
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2022-24429
convert-svg-core General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

CVE-2023-34353
OAS Platform General
7.5
HIGH
EPSS
0.0%
2023 CWE-330 1 PoC

An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-42489
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-732 1 PoC

EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource

CVE-2021-3804
nervjs/taro General
7.5
HIGH
EPSS
0.2%
2021 CWE-1333 1 PoC

taro is vulnerable to Inefficient Regular Expression Complexity

CVE-2023-27653
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files.

CVE-2023-22551
Software Genérico General
7.5
HIGH
EPSS
9.2%
2023 1 PoC

The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. This occurs because malloc is used but free is not.

CVE-2023-28450
Software Genérico General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVE-2025-44044
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.

CVE-2020-13573
Rockwell Automation General
7.5
HIGH
EPSS
8.9%
2020 CWE-823 1 PoC

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVE-2023-2251
eemeli/yaml General
7.5
HIGH
EPSS
0.5%
2023 CWE-248 1 PoC

Uncaught Exception in GitHub repository eemeli/yaml prior to 2.0.0-5.

CVE-2023-30082
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.

CVE-2025-61104
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2023-25283
Software Genérico General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.

CVE-2023-37216
SensMini M4 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device

CVE-2023-40280
Software Genérico General
7.5
HIGH
EPSS
1.3%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

CVE-2025-52513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds write, leading to a denial of service.

CVE-2021-27628
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher) General
7.5
HIGH
EPSS
0.3%
2021 CWE-787 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method DpRTmPrepareReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed o

CVE-2016-9036
Msgpuck library General
7.5
HIGH
EPSS
1.3%
2016 CWE-125 2 PoCs

An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.