40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24498
ProSAFE 24 Port 10/100 FS726TP General
7.5
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

CVE-2023-34397
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.

CVE-2023-24500
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-33263
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.

CVE-2020-7771
asciitable.js General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

CVE-2025-22387
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 CWE-598 1 PoC

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.

CVE-2023-20522
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

CVE-2023-0464
OpenSSL General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.

CVE-2023-24503
OSK201 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-6245
Candid General
7.5
HIGH
EPSS
0.1%
2023 CWE-835 1 PoC

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the canister interface expects `record { * }` then the Rust candid decoder treats empty as an extra field required by the type. The problem with the type empty is that the candid Rust library wrongly categorizes empty as a recoverable error when skipping the field and thus causing an infinite decoding loop. Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefi

CVE-2020-7772
doc-path General
7.5
HIGH
EPSS
0.8%
2020 1 PoC

This affects the package doc-path before 2.1.2.

CVE-2023-29748
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2022-41684
OpenImageIO General
7.5
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-32485
CPG BIOS General
7.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-25895
lite-dev-server General
7.5
HIGH
EPSS
1.4%
2022 1 PoC

All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.

CVE-2022-1284
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing denial of service.

CVE-2022-45124
KingHistorian General
7.5
HIGH
EPSS
5.6%
2022 CWE-200 2 PoCs

An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff network traffic to leverage this vulnerability.

CVE-2022-33077
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

CVE-2025-57430
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials.

CVE-2025-53694
Sitecore Experience Manager (XM) General
7.5
HIGH
EPSS
0.1%
2025 CWE-200 5 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.