Vulnerabilidades em unspecified

259 resultados
Análise Vexday

Com 259 CVEs catalogadas e nenhuma registrada em exploração ativa no CISA KEV, este conjunto apresenta taxa de exploração abaixo da média geral do catálogo. Ainda assim, o score EPSS de 0,5366 associado à CVE-2018-8021 — a vulnerabilidade de maior risco atual no conjunto — indica probabilidade não trivial de exploração, merecendo atenção mesmo na ausência de exploração confirmada. A falha mais recorrente é classificada como CWE-707, relacionada a problemas de neutralização inadequada de dados, e há duas vulnerabilidades com prova de conceito pública disponível, o que eleva o risco potencial mesmo sem incidentes registrados. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no perfil de exposição, mas a presença de PoCs públicas recomenda monitoramento contínuo.

CVE-2019-3879MEDIUMIt was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the peEPSS 1.8%CVE-2016-9601MEDIUMghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_imagEPSS 1.8%CVE-2020-10282CRITICALRVD#3316: No authentication in MAVLink protocolEPSS 1.7%CVE-2016-15004HIGHInfiniteWP Client Plugin injectionEPSS 1.7%CVE-2018-1074HIGHovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentialEPSS 1.5%CVE-2021-4229MEDIUMua-parser-js Crypto Mining backdoorEPSS 1.4%CVE-2020-36542HIGHDemokratian install3.php privileges managementEPSS 1.4%CVE-2022-1248HIGHSAP Information System POST Request add_admin.php improper authenticationEPSS 1.3%CVE-2016-9592MEDIUMopenshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation tEPSS 1.3%CVE-2022-3705MEDIUMvim autocmd quickfix.c qf_update_buffer use after freeEPSS 1.3%CVE-2022-3970MEDIUMLibTIFF tif_getimage.c TIFFReadRGBATileExt integer overflowEPSS 1.2%CVE-2017-20052MEDIUMPython pgAdmin4 uncontrolled search pathEPSS 1.2%CVE-2022-1837MEDIUMHome Clean Services Management System unrestricted uploadEPSS 1.2%CVE-2017-20123HIGHViscosity DLL untrusted search pathEPSS 1.2%CVE-2017-20127HIGHKB Login Authentication Script sql injectionEPSS 1.2%CVE-2020-36541HIGHDemokratian genera_select.php sql injectionEPSS 1.2%CVE-2016-9590MEDIUMpuppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation oEPSS 1.2%CVE-2021-4231LOWAngular Comment cross site scriptingEPSS 1.1%CVE-2017-20099HIGHAnalytics Stats Counter Statistics Plugin code injectionEPSS 1.1%CVE-2017-20067HIGHHindu Matrimonial Script sql injectionEPSS 1.1%