94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0570
mruby/mruby General
8.4
HIGH
EPSS
0.2%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

CVE-2022-0714
vim/vim General
8.4
HIGH
EPSS
0.3%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.

CVE-2022-0351
vim/vim General
8.4
HIGH
EPSS
0.1%
2022 CWE-786 3 PoCs

Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

CVE-2022-1276
mruby/mruby General
8.4
HIGH
EPSS
0.8%
2022 CWE-125 1 PoC

Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-0943
vim/vim General
8.4
HIGH
EPSS
0.2%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.

CVE-2022-0554
vim/vim General
8.4
HIGH
EPSS
1.2%
2022 CWE-823 2 PoCs

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

CVE-2022-4863
usememos/memos General
8.4
HIGH
EPSS
0.2%
2022 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1258
McAfee Agent ePO extension Database
8.4
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.

CVE-2022-0572
vim/vim General
8.4
HIGH
EPSS
1.8%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-2054
nuitka/nuitka General
8.4
HIGH
EPSS
0.1%
2022 CWE-94 1 PoC

Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

CVE-2006-1078
Software Genérico Web
8.4
HIGH
EPSS
0.2%
2006 4 PoCs

Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

CVE-2024-41309
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

CVE-2026-42881
STIGQter General
8.4
HIGH
EPSS
0.0%
2026 CWE-22 2 PoCs

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly run the "Export HTML" action. This vulnerability is fixed in 1.2.7.

CVE-2024-41308
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

CVE-2024-43882
Linux General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid usage When opening a file for exec via do_filp_open(), permission checking is done against the file's metadata at that moment, and on success, a file pointer is passed back. Much later in the execve() code path, the file metadata (specifically mode, uid, and gid) is used to determine if/how to set the uid and gid. However, those values may have changed since the permissions check, meaning the execution may gain unintended privileges. For example, if a file could change per

CVE-2014-0784
CENTUM CS 3000 General
8.3
UNKNOWN
EPSS
2.5%
2014 CWE-121 2 PoCs

Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

CVE-2014-0782
CENTUM CS 3000 General
8.3
UNKNOWN
EPSS
39.8%
2014 CWE-121 1 PoC

Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.

CVE-2026-0562
parisneo/lollms Web Networking
8.3
HIGH
EPSS
0.0%
2026 CWE-863 1 PoC

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Direct Object Reference (IDOR) attacks. Specifically, the `/api/friends/requests/{friendship_id}` endpoint fails to verify whether the authenticated user is part of the friendship or the intended recipient of the request. This vulnerability can lead to unauthorized access, privacy violations, and poten

CVE-2026-0603
Software Genérico Database
8.3
HIGH
EPSS
0.1%
2026 CWE-89 1 PoC

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.

CVE-2026-22219
Chainlit Web Database Cloud
8.3
HIGH
EPSS
0.0%
2026 CWE-918 1 PoC

Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with the SQLAlchemy data layer backend. An authenticated client can provide a user-controlled url value in an Element, which is fetched by the SQLAlchemy element creation logic using an outbound HTTP GET request. This allows an attacker to make arbitrary HTTP requests from the Chainlit server to internal network services or cloud metadata endpoints and store the retrieved responses via the configured storage provider.