1080 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2015-4902
🔥 KEV Software Genérico Database
5.3
MEDIUM
EPSS
18.1%
2015 1 PoC

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVE-2024-8069
🔥 KEV Citrix Session Recording Networking
5.1
MEDIUM
EPSS
66.3%
2024 CWE-502 1 PoC

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

CVE-2022-22265
🔥 KEV Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.2%
2022 CWE-703 1 PoC

An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

CVE-2012-0518
🔥 KEV Software Genérico Database
4.7
MEDIUM
EPSS
20.9%
2012 2 PoCs

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

CVE-2025-47827
🔥 KEV Software Genérico General
4.6
MEDIUM
EPSS
0.9%
2025 1 PoC

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CVE-2023-21492
🔥 KEV Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2021-25337
🔥 KEV Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.8%
2021 CWE-269 2 PoCs

Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

CVE-2017-0059
🔥 KEV Internet Explorer General
4.3
MEDIUM
EPSS
83.6%
2017 3 PoCs

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

CVE-2025-47813
🔥 KEV Wing FTP Server General ⚡ nuclei
4.3
MEDIUM
EPSS
25.0%
2025 CWE-209 2 PoCs

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVE-2020-4430
🔥 KEV Data Risk Manager General
4.3
MEDIUM
EPSS
83.8%
2020 2 PoCs

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.

CVE-2020-8196
🔥 KEV Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking
4.3
MEDIUM
EPSS
68.1%
2020 CWE-284 2 PoCs

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

CVE-2018-13374
🔥 KEV Fortinet FortiOS, fortiADC Networking Windows
4.3
MEDIUM
EPSS
3.8%
2018 1 PoC

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVE-2018-13383
🔥 KEV Fortinet FortiOS and FortiProxy Web Networking
4.3
MEDIUM
EPSS
1.8%
2018 1 PoC

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.

CVE-2013-2423
🔥 KEV Software Genérico Database
3.7
LOW
EPSS
93.4%
2013 2 PoCs

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manage

CVE-2022-23134
🔥 KEV Frontend Web ⚡ nuclei
3.7
LOW
EPSS
92.6%
2022 CWE-284 1 PoC

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVE-2023-26083
🔥 KEV Software Genérico General
3.3
LOW
EPSS
5.2%
2023 1 PoC

Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

CVE-2021-25489
🔥 KEV Samsung Mobile Devices General
3.3
LOW
EPSS
0.4%
2021 CWE-20 1 PoC

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

CVE-2021-44168
🔥 KEV Fortinet FortiOS Networking
3.3
LOW
EPSS
1.1%
2021 1 PoC

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages.

CVE-2025-47729
🔥 KEV archiving backend General
1.9
LOW
EPSS
4.1%
2025 CWE-912 1 PoC

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.