40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-2961
glibc General
7.3
HIGH
EPSS
91.9%
2024 CWE-787 12 PoCs

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

CVE-2022-22521
Benchmark Programming Tool General
7.3
HIGH
EPSS
0.1%
2022 CWE-732 2 PoCs

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

CVE-2025-26125
Software Genérico General
7.3
HIGH
EPSS
0.1%
2025 1 PoC

An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

CVE-2020-28441
conf-cfg-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-28895
Software Genérico General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVE-2023-32493
PowerScale OneFS General
7.3
HIGH
EPSS
0.4%
2023 CWE-693 1 PoC

Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

CVE-2022-32543
Alyac General
7.3
HIGH
EPSS
0.2%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2025-28020
Software Genérico General
7.3
HIGH
EPSS
0.3%
2025 2 PoCs

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

CVE-2024-40506
Software Genérico General
7.3
HIGH
EPSS
6.2%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

CVE-2025-9966
P series (P07, P10, P12, P15) General
7.3
HIGH
EPSS
0.0%
2025 CWE-269 2 PoCs

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9).

CVE-2024-12577
Graphics DDK General
7.3
HIGH
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2025-48548
Android General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CVE-2018-15610
IP Office General
7.3
HIGH
EPSS
0.6%
2018 CWE-284 1 PoC

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

CVE-2024-34660
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2025-21058
Routines General
7.3
HIGH
EPSS
0.0%
2025 1 PoC

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code with SystemUI privilege.

CVE-2018-1122
procps-ng, procps General
7.3
HIGH
EPSS
0.3%
2018 CWE-829 3 PoCs

procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vulnerabilities in the config_file() function.

CVE-2023-0817
gpac/gpac General
7.3
HIGH
EPSS
0.1%
2023 CWE-126 1 PoC

Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2022-1795
gpac/gpac General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.

CVE-2023-31348
μProf Tool General
7.3
HIGH
EPSS
0.2%
2023 1 PoC

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2020-7778
systeminformation General
7.3
HIGH
EPSS
1.1%
2020 1 PoC

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.