40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-38499
CA Client Automation (ITCM) General
7.3
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.

CVE-2024-42471
toolkit General
7.3
HIGH
EPSS
7.7%
2024 CWE-22 1 PoC

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

CVE-2024-21541
dom-iterator General
7.3
HIGH
EPSS
0.3%
2024 CWE-94 2 PoCs

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.

CVE-2023-37013
Software Genérico General
7.3
HIGH
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading to denial of service.

CVE-2023-4322
radareorg/radare2 General
7.3
HIGH
EPSS
0.2%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

CVE-2025-43948
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

CVE-2023-24059
Software Genérico General
7.3
HIGH
EPSS
9.3%
2023 1 PoC

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

CVE-2023-7261
Omaha General
7.3
HIGH
EPSS
0.0%
2023 2 PoCs

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

CVE-2025-28018
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

CVE-2024-1302
Monitool General
7.3
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

CVE-2024-0294
LR1200GB General
7.3
HIGH
EPSS
2.1%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-40109
Android General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2023-0288
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

CVE-2025-28022
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2025-49144
notepad-plus-plus General
7.3
HIGH
EPSS
0.1%
2025 CWE-272 13 PoCs

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This is

CVE-2024-40507
Software Genérico General
7.3
HIGH
EPSS
7.8%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

CVE-2024-4582
GM8181 General
7.3
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-263304.

CVE-2024-45492
Software Genérico General
7.3
HIGH
EPSS
2.3%
2024 2 PoCs

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2023-34233
snowflake-connector-python General
7.3
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then

CVE-2024-3204
c-blosc2 General
7.3
HIGH
EPSS
0.6%
2024 CWE-122 2 PoCs

A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-259051.