40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-47035
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

RPTC 0x3b08c was discovered to not conduct status checks on the parameter tradingOpen. This vulnerability can allow attackers to conduct unauthorized transfer operations.

CVE-2021-25215
BIND9 General
7.5
HIGH
EPSS
1.5%
2021 1 PoC

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.

CVE-2023-26113
collection.js General
7.5
HIGH
EPSS
0.2%
2023 CWE-1321 1 PoC

Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.

CVE-2023-32235
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2023 2 PoCs

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.

CVE-2023-25016
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

CVE-2020-7793
ua-parser-js General
7.5
HIGH
EPSS
2.6%
2020 4 PoCs

The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

CVE-2022-36537
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.9%
2022 4 PoCs

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CVE-2025-43706
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 2 PoCs

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920, W930, Modem 5123, and Modem 5400. Incorrect handling of RRC packets leads to a Denial of Service.

CVE-2023-27705
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.

CVE-2023-6020
ray-project/ray General ⚡ nuclei
7.5
HIGH
EPSS
81.4%
2023 CWE-862 1 PoC

LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.

CVE-2023-42487
Soundminer General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2022-24400
TETRA Standard General
7.5
HIGH
EPSS
0.2%
2022 CWE-807 1 PoC

A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.

CVE-2023-26071
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.

CVE-2023-26105
utilities General
7.5
HIGH
EPSS
0.2%
2023 CWE-1321 1 PoC

All versions of the package utilities are vulnerable to Prototype Pollution via the _mix function.

CVE-2023-31181
InnoKB Server, InnoKB/Console General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal

CVE-2023-26141
sidekiq General
7.5
HIGH
EPSS
0.4%
2023 CWE-400 1 PoC

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVE-2023-32111
SAP PowerDesigner (Proxy) General
7.5
HIGH
EPSS
0.3%
2023 CWE-787 1 PoC

In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application.

CVE-2023-27191
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.

CVE-2023-7005
TTLock App General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.

CVE-2023-4698
usememos/memos General
7.5
HIGH
EPSS
1.7%
2023 CWE-20 2 PoCs

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.