40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-27601
opensips General
7.5
HIGH
EPSS
0.8%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by the `delete_sdp_line` function in the sipmsgops module. This issue can be reproduced by calling the function with an SDP body that does not terminate by a line feed (i.e. `\n`). The vulnerability was found while performing black-box fuzzing against an OpenSIPS server running a configuration that made use of the functions `codec_delete_except_re` and `codec_delete_re`. The same issue was also discovered while perfor

CVE-2023-26106
dot-lens General
7.5
HIGH
EPSS
0.3%
2023 CWE-1321 1 PoC

All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.

CVE-2023-34609
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 4 PoCs

An issue was discovered flexjson thru 3.3 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVE-2022-41404
Software Genérico General
7.5
HIGH
EPSS
0.8%
2022 2 PoCs

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVE-2025-51868
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.

CVE-2023-44837
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-32309
pymdown-extensions General
7.5
HIGH
EPSS
3.5%
2023 CWE-22 1 PoC

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when using include file syntax. By using the syntax `--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the generated documentation. Additionally, a path relative to a specified, allowed base path can also be used to render the content of a file outside the specified base paths: `--8<-- "../../../../etc/passwd"`. Within the Snippets extension, there exists a `base_path` option but the implementation is vul

CVE-2020-7683
rollup-plugin-server General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.

CVE-2025-55972
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This denial persists as long as the attack continues and affects all forms of TV operation. Manual user control and even reboots do not restore functionality unless the flood stops.

CVE-2018-4026
Novatek General
7.5
HIGH
EPSS
0.3%
2018 1 PoC

An exploitable denial-of-service vulnerability exists in the XML_GetScreen Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted set of packets can cause an invalid memory dereference, resulting in a device reboot.

CVE-2023-47035
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.

CVE-2021-30304
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity

CVE-2012-0039
Software Genérico General
7.5
HIGH
EPSS
0.5%
2012 1 PoC

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

CVE-2021-26406
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
7.5
HIGH
EPSS
0.2%
2021 2 PoCs

Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.

CVE-2023-26113
collection.js General
7.5
HIGH
EPSS
0.2%
2023 CWE-1321 1 PoC

Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.

CVE-2023-25016
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

CVE-2023-49545
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2022-25904
safe-eval General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.

CVE-2023-42487
Soundminer General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')