9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2016-20034
Wowza Streaming Engine General
8.7
HIGH
EPSS
0.0%
2016 CWE-352 2 PoCs

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.

CVE-2016-15055
IP-Camera (VN-T216VPRU) General
8.7
HIGH
EPSS
1.5%
2016 CWE-22 1 PoC

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

CVE-2018-25139
FLIR AX8 Thermal Camera General
8.7
HIGH
EPSS
0.2%
2018 CWE-306 2 PoCs

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.

CVE-2018-25246
Wikipedia General
8.7
HIGH
EPSS
0.0%
2018 CWE-306 1 PoC

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.

CVE-2018-25144
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Arbitrary File Attacks General
8.7
HIGH
EPSS
0.3%
2018 CWE-22 2 PoCs

Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system modifications through GET and POST requests.

CVE-2018-25245
7 Tik General
8.7
HIGH
EPSS
0.1%
2018 CWE-601 1 PoC

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

CVE-2018-25308
Buddypress Xprofile Custom Fields Type General
8.7
HIGH
EPSS
0.3%
2018 CWE-22 1 PoC

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server.

CVE-2018-25294
CEWE Photoshow General
8.7
HIGH
EPSS
0.1%
2018 CWE-120 1 PoC

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

CVE-2018-25113
PACS Web Server General
8.7
HIGH
EPSS
42.8%
2018 CWE-22 2 PoCs

An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remote attackers to read arbitrary files on the underlying system by sending a crafted request to the /exportFile endpoint using the UID parameter. Successful exploitation can reveal sensitive files accessible by the web server user.

CVE-2018-25193
Mongoose Web Server General
8.7
HIGH
EPSS
0.1%
2018 CWE-1188 1 PoC

Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unavailability.

CVE-2018-25181
Musicco General
8.7
HIGH
EPSS
1.1%
2018 CWE-22 1 PoC

Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download them as ZIP files.

CVE-2018-25164
EverSync General
8.7
HIGH
EPSS
0.1%
2018 CWE-552 1 PoC

EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to download database files like db.sq3 containing application data and credentials.

CVE-2018-25136
Brickstream 3D+ General
8.7
HIGH
EPSS
0.1%
2018 CWE-306 2 PoCs

FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can retrieve video stream images by directly accessing multiple image endpoints like middleImage.jpg, rightimage.jpg, and leftimage.jpg.

CVE-2018-25141
FLIR Thermal Traffic Cameras General
8.7
HIGH
EPSS
0.2%
2018 CWE-306 2 PoCs

FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.

CVE-2010-10014
Odin Secure FTP General
8.7
HIGH
EPSS
61.3%
2010 CWE-121 2 PoCs

Odin Secure FTP <= 4.1 is vulnerable to a stack-based buffer overflow when parsing directory listings received in response to an FTP LIST command. A malicious FTP server can send an overly long filename in the directory listing, which overflows a fixed-size stack buffer in the client and overwrites the Structured Exception Handler (SEH). This allows remote attackers to execute arbitrary code on the client system.

CVE-2011-10029
Solar FTP Server General
8.7
HIGH
EPSS
48.8%
2011 CWE-134 2 PoCs

Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition.

CVE-2011-10014
San Andreas Multiplayer General
8.7
HIGH
EPSS
2.3%
2011 CWE-121 3 PoCs

GTA San Andreas Multiplayer (SA-MP) server version 0.3.1.1 is vulnerable to a stack-based buffer overflow triggered by parsing a malformed server.cfg configuration file. The vulnerability allows local attackers to execute arbitrary code when the server binary (samp-server.exe) processes a crafted echo directive containing excessive input. The original 'sa-mp.com' site is defunct, but the community maintains mirrors and forks that may be vulnerable.

CVE-2011-10020
Server General
8.7
HIGH
EPSS
51.4%
2011 CWE-20 2 PoCs

Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet after the initial handshake. Once a client sends a valid HELLO0.83 packet and receives a response, any subsequent malformed packet causes the server to crash and become unresponsive. This flaw stems from improper input validation in the server’s UDP packet handler, allowing unauthenticated remote attackers to disrupt service availability.

CVE-2022-38123
GateManager General
8.7
HIGH
EPSS
0.5%
2022 CWE-20 1 PoC

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.

CVE-2022-41800
BIG-IP General ⚡ nuclei
8.7
HIGH
EPSS
92.7%
2022 CWE-77 0 PoCs

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.