Vulnerabilidades en unspecified

259 resultados
Análisis Vexday

Com 259 CVEs catalogadas e nenhuma registrada em exploração ativa no CISA KEV, este conjunto apresenta taxa de exploração abaixo da média geral do catálogo. Ainda assim, o score EPSS de 0,5366 associado à CVE-2018-8021 — a vulnerabilidade de maior risco atual no conjunto — indica probabilidade não trivial de exploração, merecendo atenção mesmo na ausência de exploração confirmada. A falha mais recorrente é classificada como CWE-707, relacionada a problemas de neutralização inadequada de dados, e há duas vulnerabilidades com prova de conceito pública disponível, o que eleva o risco potencial mesmo sem incidentes registrados. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no perfil de exposição, mas a presença de PoCs públicas recomenda monitoramento contínuo.

CVE-2018-25043MEDIUMuTorrent PRNG improper authenticationEPSS 1.2%CVE-2017-20101LOWProjectSend information disclosureEPSS 1.1%CVE-2017-20128HIGHKB Messages PHP Script sql injectionEPSS 1.1%CVE-2017-20104HIGHSimplessus Cookie Time sql injectionEPSS 1.1%CVE-2016-9590MEDIUMpuppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation oEPSS 1.1%CVE-2022-3959LOWdrogon Session Hash small space of random valuesEPSS 1.1%CVE-2018-1079HIGHpcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of tEPSS 1.1%CVE-2017-20086MEDIUMVaultPress Plugin code injectionEPSS 1.1%CVE-2022-4011MEDIUMSimple History Plugin Header neutralization for logsEPSS 1.0%CVE-2017-20105MEDIUMSimplessus path traversalEPSS 1.0%CVE-2022-3299MEDIUMOpen5GS AMF client.c denial of serviceEPSS 1.0%CVE-2022-3957MEDIUMGPAC SVG Parser svg_attributes.c svg_parse_preserveaspectratio memory leakEPSS 1.0%CVE-2018-25041MEDIUMuTorrent JSON RPC Server privileges managementEPSS 1.0%CVE-2018-25042MEDIUMuTorrent memory corruptionEPSS 1.0%CVE-2022-1838MEDIUMHome Clean Services Management System login.php sql injectionEPSS 1.0%CVE-2016-9593MEDIUMforeman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file woulEPSS 1.0%CVE-2017-20103MEDIUMKama Click Counter Plugin admin.php Blind sql injectionEPSS 1.0%CVE-2018-25044MEDIUMuTorrent Guest Account privileges managementEPSS 1.0%CVE-2016-15002HIGHMONyog Ultimate Cookie privileges managementEPSS 1.0%CVE-2017-20126HIGHKB Affiliate Referral Script index.php sql injectionEPSS 1.0%