40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0509
pyload/pyload General
7.4
HIGH
EPSS
0.1%
2023 CWE-295 1 PoC

Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.

CVE-2012-3372
Software Genérico General
7.4
HIGH
EPSS
0.1%
2012 1 PoC

The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the presence of the Cyberoam_SSL_CA certificate in a list of trusted root certification authorities. NOTE: the vendor disputes the significance of this issue because the appliance "does not allow import or export of the foresaid private key.

CVE-2023-5393
Experion Server General
7.4
HIGH
EPSS
1.2%
2023 CWE-130 1 PoC

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-26145
pydash General
7.4
HIGH
EPSS
1.8%
2023 CWE-78 1 PoC

This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects. **Note:** The pydash.objects.invoke() method is vulnerable to Command Injection when the following prerequisites are satisfied: 1) The source object (argument 1) is not a built-in object such as list/d

CVE-2024-27052
Linux General
7.4
HIGH
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work The workqueue might still be running, when the driver is stopped. To avoid a use-after-free, call cancel_work_sync() in rtl8xxxu_stop().

CVE-2025-69419
OpenSSL General
7.4
HIGH
EPSS
0.1%
2025 CWE-787 1 PoC

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes, the helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16

CVE-2022-26964
Software Genérico General
7.4
HIGH
EPSS
0.3%
2022 1 PoC

Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.

CVE-2022-25855
create-choo-app3 General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-0129
McAfee TechCheck General
7.4
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

CVE-2023-5396
Experion Server General
7.4
HIGH
EPSS
0.9%
2023 CWE-805 1 PoC

Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-1514
RTU500 Scripting Interface General
7.4
HIGH
EPSS
0.1%
2023 CWE-295 1 PoC

A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting

CVE-2021-33540
AXL F BK General
7.3
HIGH
EPSS
0.2%
2021 CWE-798 1 PoC

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

CVE-2022-1052
radareorg/radare2 General
7.3
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2021-3928
vim/vim General
7.3
HIGH
EPSS
0.0%
2021 CWE-457 1 PoC

vim is vulnerable to Use of Uninitialized Variable

CVE-2021-25495
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-122 1 PoC

A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

CVE-2018-10877
kernel General
7.3
HIGH
EPSS
0.2%
2018 CWE-125 2 PoCs

Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.

CVE-2021-23440
set-value General
7.3
HIGH
EPSS
0.1%
2021 4 PoCs

This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

CVE-2021-32553
apport General
7.3
HIGH
EPSS
0.0%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.

CVE-2021-23682
litespeed.js General
7.3
HIGH
EPSS
5.4%
2021 2 PoCs

This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.