40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-43948
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 1 PoC

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

CVE-2022-1795
gpac/gpac General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2017-20111
WFM General
7.3
HIGH
EPSS
0.4%
2017 CWE-269 1 PoC

A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2024-34612
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-43688
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

CVE-2025-28022
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2024-38355
socket.io General
7.3
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2` (released in May 2023). The fix was backported in the 2.x branch as well with commit `d30630ba10`. Users are advised to upgrade. Users unable to upgrade may attach a listener for the "error" event to catch these errors.

CVE-2025-9966
P series (P07, P10, P12, P15) General
7.3
HIGH
EPSS
0.0%
2025 CWE-269 2 PoCs

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2024-34656
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2023-0760
gpac/gpac General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.

CVE-2023-31349
μProf Tool General
7.3
HIGH
EPSS
0.2%
2023 CWE-276 1 PoC

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2024-20878
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-28287
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.

CVE-2025-28020
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2024-13966
BioTime General
7.3
HIGH
EPSS
0.6%
2024 CWE-1393 1 PoC

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

CVE-2024-43093
🔥 KEV Android General
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-2961
glibc General
7.3
HIGH
EPSS
91.9%
2024 CWE-787 12 PoCs

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVE-2018-15610
IP Office General
7.3
HIGH
EPSS
0.6%
2018 CWE-284 1 PoC

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

CVE-2018-1122
procps-ng, procps General
7.3
HIGH
EPSS
0.3%
2018 CWE-829 3 PoCs

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.

CVE-2020-28461
js-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.