40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-21441
Routine General
7.4
HIGH
EPSS
0.0%
2023 CWE-345 1 PoC

Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.

CVE-2024-31320
Android General
7.4
HIGH
EPSS
0.7%
2024 1 PoC

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2022-0432
mastodon/mastodon General ⚡ nuclei
7.4
HIGH
EPSS
57.1%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

CVE-2024-27147
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2022-25962
vagrant.js General
7.4
HIGH
EPSS
0.7%
2022 CWE-78 1 PoC

All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

CVE-2020-4574
Security Key Lifecycle Manager General
7.4
HIGH
EPSS
0.3%
2020 1 PoC

IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.

CVE-2024-27152
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2022-1253
strukturag/libde265 General
7.4
HIGH
EPSS
0.5%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.

CVE-2023-42560
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.1%
2023 1 PoC

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

CVE-2022-1155
snipe/snipe-it General
7.4
HIGH
EPSS
0.3%
2022 CWE-840 1 PoC

Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

CVE-2024-27150
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2022-39299
passport-saml General
7.4
HIGH
EPSS
4.6%
2022 CWE-347 8 PoCs

Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to passport-saml version 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before

CVE-2023-26459
NetWeaver AS for ABAP and ABAP Platform General
7.4
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.

CVE-2022-25923
exec-local-bin General
7.4
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

CVE-2024-27151
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.6%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.

CVE-2024-27149
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2017-12094
Circle General
7.4
HIGH
EPSS
0.3%
2017 1 PoC

An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this vulnerability.

CVE-2024-27171
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
1.7%
2024 CWE-276 1 PoC

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

CVE-2021-38515
Software Genérico General
7.4
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects R6400v2 before 1.0.4.98, R6700v3 before 1.0.4.98, R7900 before 1.0.3.18, and R8000 before 1.0.4.46.

CVE-2024-20767
🔥 KEV ColdFusion General ⚡ nuclei
7.4
HIGH
EPSS
94.0%
2024 CWE-284 6 PoCs

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.