40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-1999-1568
Software Genérico General
7.5
HIGH
EPSS
1.7%
1999 1 PoC

Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

CVE-2022-24412
PowerScale OneFS General
7.5
HIGH
EPSS
0.5%
2022 CWE-229 1 PoC

Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.

CVE-2022-38840
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
58.1%
2022 1 PoC

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.

CVE-2022-41684
OpenImageIO General
7.5
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-23990
Software Genérico General
7.5
HIGH
EPSS
3.7%
2022 3 PoCs

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVE-2025-66959
Software Genérico General
7.5
HIGH
EPSS
0.3%
2025 1 PoC

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

CVE-2025-2520
C300 PCNT02 General
7.5
HIGH
EPSS
0.4%
2025 CWE-457 1 PoC

The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications. An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which results in a dereferencing of an uninitialized pointer leading to a denial of service. Honeywell recommends updating to the most recent version of Honeywell Experion PKS: 520.2 TCU9 HF1and 530.1 TCU3 HF1. The affected Experion PKS products are C300 PCNT02, EHB, EHPM, ELMM, Classic ENIM, ETN, FIM4, FIM8, PGM, and RFIM. The Experion PKS versions affected are

CVE-2023-5590
seleniumhq/selenium General
7.5
HIGH
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVE-2023-36667
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

CVE-2023-44835
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-24506
NCR/Camera General
7.5
HIGH
EPSS
0.3%
2023 CWE-522 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

CVE-2023-40297
Software Genérico General
7.5
HIGH
EPSS
3.1%
2023 1 PoC

Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.

CVE-2023-44828
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-24033
Software Genérico General
7.5
HIGH
EPSS
1.8%
2023 2 PoCs

The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.

CVE-2023-23131
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

CVE-2020-28442
js-data General
7.5
HIGH
EPSS
0.6%
2020 3 PoCs

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

CVE-2020-22660
Software Genérico General
7.5
HIGH
EPSS
0.3%
2020 1 PoC

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to force bypass Secure Boot failed attempts and run temporarily the previous Backup image.

CVE-2023-42488
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-27159
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
80.2%
2023 0 PoCs

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

CVE-2025-70238
Software Genérico General
7.5
HIGH
EPSS
0.1%
2025 1 PoC

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.