40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3777
daaku/nodejs-tmpl General
7.5
HIGH
EPSS
0.4%
2021 CWE-1333 1 PoC

nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity

CVE-2025-27594
SICK DL100-2xxxxxxx General
7.5
HIGH
EPSS
0.1%
2025 CWE-319 1 PoC

The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a pass-the-hash attack.

CVE-2023-42488
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-27159
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
80.2%
2023 0 PoCs

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

CVE-2023-29929
Software Genérico General
7.5
HIGH
EPSS
2.8%
2023 2 PoCs

Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

CVE-2025-44044
Software Genérico General
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.

CVE-2020-7682
marked-tree General
7.5
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.

CVE-2023-44835
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-49981
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2015-3035
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2015 2 PoCs

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

CVE-2021-21963
Sealevel General
7.4
HIGH
EPSS
0.1%
2021 CWE-311 1 PoC

An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2021-32723
prism General
7.4
HIGH
EPSS
0.4%
2021 CWE-400 1 PoC

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.

CVE-2021-38917
PowerVM Hypervisor General
7.4
HIGH
EPSS
0.3%
2021 1 PoC

IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.

CVE-2022-24377
cycle-import-check General
7.4
HIGH
EPSS
1.4%
2022 1 PoC

The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

CVE-2021-21004
FL SWITCH General
7.4
HIGH
EPSS
0.2%
2021 CWE-79 1 PoC

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

CVE-2022-25916
mt7688-wiscan General
7.4
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

CVE-2019-5108
Linux kernel General
7.4
HIGH
EPSS
0.8%
2019 CWE-440 4 PoCs

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

CVE-2019-14868
ksh General
7.4
HIGH
EPSS
0.2%
2019 CWE-77 1 PoC

In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

CVE-2019-20653
Software Genérico General
7.4
HIGH
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

CVE-2019-5061
W1.f1 General
7.4
HIGH
EPSS
0.3%
2019 CWE-440 1 PoC

An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.