1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-50302
🔥 KEV Linux General
5.5
MEDIUM
EPSS
1.7%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

CVE-2023-6548
🔥 KEV NetScaler ADC General
5.5
MEDIUM
EPSS
8.3%
2023 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CVE-2023-4211
🔥 KEV Midgard GPU Kernel Driver General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVE-2023-41991
🔥 KEV iOS and iPadOS General
5.5
MEDIUM
EPSS
3.5%
2023 1 PoC

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2014-0196
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
48.6%
2014 5 PoCs

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

CVE-2013-3900
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
74.4%
2013 CWE-347 12 PoCs

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verificatio

CVE-2020-27950
🔥 KEV watchOS General
5.5
MEDIUM
EPSS
43.8%
2020 2 PoCs

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

CVE-2020-1472
🔥 KEV Windows Server version 2004 Windows
5.5
MEDIUM
EPSS
94.4%
2020 59 PoCs

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by

CVE-2020-9934
🔥 KEV iOS General
5.5
MEDIUM
EPSS
2.4%
2020 1 PoC

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

CVE-2016-4655
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
81.7%
2016 1 PoC

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

CVE-2021-30657
🔥 KEV macOS General
5.5
MEDIUM
EPSS
83.1%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-27562
🔥 KEV Software Genérico General
5.5
MEDIUM
EPSS
44.5%
2021 1 PoC

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41049
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
13.1%
2022 3 PoCs

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2026-20122
🔥 KEV Cisco Catalyst SD-WAN Manager Web Networking
5.4
MEDIUM
EPSS
1.1%
2026 CWE-648 1 PoC

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmana

CVE-2013-5223
🔥 KEV Software Genérico Web
5.4
MEDIUM
EPSS
30.1%
2013 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add acti

CVE-2025-55177
🔥 KEV WhatsApp Desktop for Mac General
5.4
MEDIUM
EPSS
0.7%
2025 1 PoC

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.