40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-36281
Software Genérico General
9.8
CRITICAL
EPSS
62.2%
2023 3 PoCs

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

CVE-2024-2921
Server General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.

CVE-2024-45488
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
86.9%
2024 0 PoCs

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

CVE-2024-6602
Firefox General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVE-2024-27776
DeviceHub General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-22 1 PoC

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

CVE-2024-24398
Software Genérico General
9.8
CRITICAL
EPSS
30.5%
2024 2 PoCs

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

CVE-2024-57604
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

CVE-2023-37903
vm2 General
9.8
CRITICAL
EPSS
36.1%
2023 CWE-78 1 PoC

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.

CVE-2024-29650
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 2 PoCs

An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

CVE-2023-24799
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-34152
ImageMagick General
9.8
CRITICAL
EPSS
69.5%
2023 CWE-20 2 PoCs

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVE-2023-29736
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

CVE-2019-17444
Artifactory General ⚡ nuclei
9.8
CRITICAL
EPSS
92.5%
2019 CWE-521 2 PoCs

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

CVE-2024-9537
🔥 KEV SL1 General
9.8
CRITICAL
EPSS
63.9%
2024 4 PoCs

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CVE-2023-51953
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2026-5442
DICOM Server General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.

CVE-2024-34832
Software Genérico General
9.8
CRITICAL
EPSS
8.3%
2024 1 PoC

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

CVE-2024-44000
LiteSpeed Cache General ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2024 CWE-522 6 PoCs

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

CVE-2023-5074
D-View 8 General ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2023 CWE-798 2 PoCs

Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28