Vulnerabilidades em [UNKNOWN]

239 resultados
Análise Vexday

Com 240 CVEs catalogadas e taxa de exploração ativa em linha com a média geral do catálogo, o perfil deste vendor não apresenta desvios alarmantes em volume, mas concentra atenção em pontos específicos. O valor máximo de EPSS observado (0,9179) indica que ao menos uma vulnerabilidade possui probabilidade muito elevada de exploração, e a CVE em exploração ativa confirmada pelo CISA KEV — CVE-2018-14667, com EPSS de 0,7417 — representa risco concreto e imediato, especialmente por ser uma falha com anos de exposição ainda não completamente mitigada em ambientes desatualizados. A falha mais comum é CWE-20 (validação inadequada de entrada), padrão que frequentemente viabiliza execução remota de código e injeção de dados maliciosos, e cuja presença recorrente sugere lacunas sistêmicas no tratamento de entradas. Com 11 CVEs com PoC pública e 7 de severidade crítica, equipes de segurança devem priorizar a verificação de exposição às vulnerabilidades com maior EPSS, mesmo na ausência de novas CVEs nos últimos 90 dias.

CVE-2018-10891MEDIUMA flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the questEPSS 2.1%CVE-2018-10890MEDIUMA flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to reEPSS 2.1%CVE-2018-10889MEDIUMA flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain EPSS 2.1%CVE-2020-10740MEDIUMA vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise ApEPSS 2.1%CVE-2016-2120HIGHAn issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash theEPSS 2.0%CVE-2018-1124HIGHprocps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allowEPSS 1.9%CVE-2018-1125HIGHprocps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involveEPSS 1.9%CVE-2018-1126MEDIUMprocps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. ThEPSS 1.9%CVE-2017-7464HIGHIt was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker coulEPSS 1.9%CVE-2018-1073MEDIUMThe web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, alloEPSS 1.9%CVE-2019-14842HIGHStructured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed EPSS 1.8%CVE-2018-14631HIGHmoodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumEPSS 1.8%CVE-2017-2609MEDIUMjenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autoEPSS 1.8%CVE-2018-1067MEDIUMIn Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerEPSS 1.8%CVE-2017-2617HIGHhawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a craEPSS 1.7%CVE-2016-6328MEDIUMA vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-ServEPSS 1.7%CVE-2019-14856MEDIUMansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a NoneEPSS 1.7%CVE-2016-6343MEDIUMJBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to EPSS 1.7%CVE-2018-10847MEDIUMprosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated wiEPSS 1.7%CVE-2017-7468MEDIUMIn curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changedEPSS 1.7%