40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-27564
Software Genérico General
7.5
HIGH
EPSS
3.9%
2023 1 PoC

The n8n package 0.218.0 for Node.js allows Information Disclosure.

CVE-2023-46346
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVE-2025-61101
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVE-2023-25289
Software Genérico General
7.5
HIGH
EPSS
13.3%
2023 1 PoC

Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.

CVE-2018-18325
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2018 1 PoC

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CVE-2023-41102
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

CVE-2023-32330
Security Verify Access Appliance General
7.5
HIGH
EPSS
0.1%
2023 CWE-295 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.

CVE-2023-35843
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.0%
2023 4 PoCs

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

CVE-2017-2893
Mongoose General
7.5
HIGH
EPSS
5.3%
2017 1 PoC

An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

CVE-2023-34609
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 4 PoCs

An issue was discovered flexjson thru 3.3 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVE-2018-3839
Simple DirectMedia General
7.5
HIGH
EPSS
1.2%
2018 1 PoC

An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

CVE-2023-27601
opensips General
7.5
HIGH
EPSS
0.8%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by the `delete_sdp_line` function in the sipmsgops module. This issue can be reproduced by calling the function with an SDP body that does not terminate by a line feed (i.e. `\n`). The vulnerability was found while performing black-box fuzzing against an OpenSIPS server running a configuration that made use of the functions `codec_delete_except_re` and `codec_delete_re`. The same issue was also discovered while perfor

CVE-2025-34093
HDX Series General
7.5
HIGH
EPSS
69.4%
2025 CWE-78 1 PoC

An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute command in the devcmds console accepts unsanitized input, allowing attackers to execute arbitrary system commands. By injecting shell metacharacters through the traceroute interface, an attacker can achieve remote code execution under the context of the root user. This flaw affects systems where Telnet access is enabled and either unauthenticated access is allowed or credentials are known.

CVE-2023-44837
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-26106
dot-lens General
7.5
HIGH
EPSS
0.3%
2023 CWE-1321 1 PoC

All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.

CVE-2008-4929
Software Genérico General
7.5
HIGH
EPSS
0.7%
2008 1 PoC

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.

CVE-2023-20522
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

CVE-2022-25885
muhammara General
7.5
HIGH
EPSS
0.9%
2022 2 PoCs

The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.

CVE-2020-6208
SAP Business Objects Business Intelligence Platform (Crystal Reports) General
7.5
HIGH
EPSS
2.6%
2020 1 PoC

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.

CVE-2020-10067
zephyr General
7.5
HIGH
EPSS
0.1%
2020 CWE-190 1 PoC

A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend on the underlying system call and can range from denial of service to information leak to memory corruption resulting in code execution within the kernel. See NCC-ZEP-005 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions. version 2.1.0 and later versions.