40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29552
🔥 KEV Software Genérico General
7.5
HIGH
EPSS
91.9%
2023 1 PoC

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

CVE-2023-48834
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

CVE-2020-36564
github.com/justinas/nosurf General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.

CVE-2020-11268
Snapdragon Auto, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

CVE-2020-9050
Metasys Reporting Engine (MRE) Web Services versions 2.0 and 2.1 General
7.5
HIGH
EPSS
0.7%
2020 1 PoC

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

CVE-2023-26575
IDWeb General
7.5
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVE-2020-7669
github.com/u-root/u-root/pkg/tarutil General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.

CVE-2025-63800
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

CVE-2022-25852
pg-native General
7.5
HIGH
EPSS
0.4%
2022 2 PoCs

All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.

CVE-2023-20529
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2023-39981
MXsecurity Series General
7.5
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of device information by a remote attacker.

CVE-2025-26785
Software Genérico General
7.5
HIGH
EPSS
0.4%
2025 2 PoCs

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

CVE-2023-49338
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVE-2023-46664
PolyEco1000 General
7.5
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages.

CVE-2020-29500
PowerStore General
7.5
HIGH
EPSS
0.0%
2020 CWE-312 1 PoC

Dell EMC PowerStore versions prior to 1.0.3.0.5.007 contain a Plain-Text Password Storage Vulnerability in PowerStore T environments. A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

CVE-2025-52513
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds write, leading to a denial of service.

CVE-2023-24709
Software Genérico General
7.5
HIGH
EPSS
32.1%
2023 4 PoCs

An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

CVE-2025-57440
Software Genérico General
7.5
HIGH
EPSS
0.0%
2025 1 PoC

The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for controlling streaming, recording, formatting storage devices, and system reboot. This interface, referred to as the "ATEM Ethernet Protocol 1.0", provides complete device control without requiring credentials or encryption. An attacker on the same network (or with remote access to the exposed port) can exploit this interface to execute arbitrary streaming commands, erase disks, or shut down the device - effectively gaining full remote control.

CVE-2023-27564
Software Genérico General
7.5
HIGH
EPSS
3.9%
2023 1 PoC

The n8n package 0.218.0 for Node.js allows Information Disclosure.

CVE-2021-27665
exacqVision Web Service General
7.5
HIGH
EPSS
0.3%
2021 CWE-190 1 PoC

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.