40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-45893
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

CVE-2022-1711
jgraph/drawio General ⚡ nuclei
7.5
HIGH
EPSS
35.4%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

CVE-2013-10057
PDF In-The-Box General
7.5
HIGH
EPSS
64.7%
2013 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy operation overwrites a saved TRegistry class pointer on the stack. This allows remote attackers to execute arbitrary code in the context of the user by enticing them to visit a malicious webpage that instantiates the vulnerable ActiveX control. The vulnerability was discovered via its use in third-party software such as Logic Prin

CVE-2023-20531
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2021-27665
exacqVision Web Service General
7.5
HIGH
EPSS
0.3%
2021 CWE-190 1 PoC

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.

CVE-2020-6208
SAP Business Objects Business Intelligence Platform (Crystal Reports) General
7.5
HIGH
EPSS
2.6%
2020 1 PoC

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.

CVE-2025-63208
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

CVE-2022-46434
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

An issue in the firmware update process of TP-Link TL-WA7510N v1 v3.12.6 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVE-2023-34467
xwiki-platform General
7.5
HIGH
EPSS
1.8%
2023 CWE-402 1 PoC

XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response was also containing the mail unobfuscated and users were able to filter and sort on the unobfuscated, allowing them to infer the mail content. The consequence was the possibility to retrieve the email addresses of all users even when obfuscated. This has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.

CVE-2023-34353
OAS Platform General
7.5
HIGH
EPSS
0.0%
2023 CWE-330 1 PoC

An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2025-25758
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

CVE-2023-6960
TTLock App General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

CVE-2023-30706
Samsung Mobile Devices General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.

CVE-2021-30330
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible null pointer dereference due to improper validation of APE clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2023-28450
Software Genérico General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVE-2023-42489
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-732 1 PoC

EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource

CVE-2023-27653
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files.

CVE-2023-25283
Software Genérico General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.

CVE-2023-22551
Software Genérico General
7.5
HIGH
EPSS
9.2%
2023 1 PoC

The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. This occurs because malloc is used but free is not.

CVE-2023-30082
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.