94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6730
huggingface/transformers General
9.0
CRITICAL
EPSS
0.2%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

CVE-2024-55585
moPS Web
9.0
CRITICAL
EPSS
0.3%
2024 CWE-306 2 PoCs

In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by /api/v1/users/resetpassword.

CVE-2024-3300
DELMIA Apriso General ⚡ nuclei
9.0
CRITICAL
EPSS
34.7%
2024 CWE-502 1 PoC

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

CVE-2024-3596
RFC General
9.0
CRITICAL
EPSS
22.2%
2024 2 PoCs

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

CVE-2024-23309
WBR-6012 Networking
9.0
CRITICAL
EPSS
0.1%
2024 CWE-291 2 PoCs

The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.

CVE-2024-0132
Container Toolkit DevOps
9.0
CRITICAL
EPSS
3.9%
2024 CWE-367 2 PoCs

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-58136
🔥 KEV Yii General ⚡ nuclei
9.0
CRITICAL
EPSS
57.5%
2024 CWE-424 1 PoC

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

CVE-2024-43415
decidim-module-decidim_awesome Database
9.0
CRITICAL
EPSS
0.3%
2024 CWE-89 1 PoC

An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.

CVE-2024-32964
lobe-chat Web ⚡ nuclei
9.0
CRITICAL
EPSS
74.1%
2024 CWE-918 0 PoCs

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

CVE-2024-55884
Software Genérico Networking
9.0
CRITICAL
EPSS
0.8%
2024 1 PoC

In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in enable() in exception_logging/unix.rs, aka MLLVD-CR-24-01. NOTE: achieving code execution is considered non-trivial.

CVE-2024-47066
lobe-chat Web
9.0
CRITICAL
EPSS
5.8%
2024 CWE-918 1 PoC

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.

CVE-2024-10773
SICK InspectorP61x General
9.0
CRITICAL
EPSS
0.4%
2024 CWE-912 1 PoC

The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.

CVE-2024-3119
sngrep General
9.0
CRITICAL
EPSS
1.9%
2024 CWE-120 1 PoC

A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers without checking the data length. This flaw allows remote attackers to execute arbitrary code or cause a denial of service (DoS) through specially crafted SIP messages.

CVE-2024-28456
Software Genérico General
9.0
CRITICAL
EPSS
0.7%
2024 1 PoC

Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.

CVE-2024-29855
Recovery Orchestrator General
9.0
CRITICAL
EPSS
19.1%
2024 1 PoC

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

CVE-2024-21400
Azure Kubernetes Service DevOps Cloud
9.0
CRITICAL
EPSS
1.6%
2024 CWE-22 1 PoC

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVE-2024-21172
Oracle Hospitality OPERA 5 Web Database
9.0
CRITICAL
EPSS
3.5%
2024 1 PoC

Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.0 (Confidentiality,

CVE-2024-42465
upKeeper Manager General
9.0
CRITICAL
EPSS
0.4%
2024 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-22144
Anti-Malware Security and Brute-Force Firewall Networking
9.0
CRITICAL
EPSS
0.7%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

CVE-2024-38124
Windows Server 2019 Windows
9.0
CRITICAL
EPSS
0.3%
2024 CWE-287 1 PoC

Windows Netlogon Elevation of Privilege Vulnerability