878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-27115
SO Planning General ⚡ nuclei
10.0
CRITICAL
EPSS
81.8%
2024 CWE-434 1 PoC

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

CVE-2024-25600
Bricks Builder General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 CWE-94 22 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

CVE-2024-31982
xwiki-platform General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-95 7 PoCs

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may manually apply the patch to the page `

CVE-2024-32651
changedetection.io General ⚡ nuclei
10.0
CRITICAL
EPSS
92.3%
2024 CWE-1336 3 PoCs

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

CVE-2024-2389
Flowmon General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 1 PoC

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

CVE-2019-4716
🔥 KEV Planning Analytics General ⚡ nuclei
10.0
CRITICAL
EPSS
93.4%
2019 3 PoCs

IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.

CVE-2021-41277
🔥 KEV metabase General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-200 13 PoCs

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the applicat

CVE-2025-10035
🔥 KEV GoAnywhere MFT General ⚡ nuclei
10.0
CRITICAL
EPSS
55.2%
2025 CWE-77 4 PoCs

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVE-2025-34040
Zhiyuan OA Web Application System General ⚡ nuclei
10.0
CRITICAL
EPSS
14.8%
2025 CWE-434 3 PoCs

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-01 UTC.

CVE-2025-47812
🔥 KEV Wing FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
92.8%
2025 CWE-158 14 PoCs

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts.

CVE-2025-49132
panel General ⚡ nuclei
10.0
CRITICAL
EPSS
15.7%
2025 CWE-94 10 PoCs

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but

CVE-2025-57819
🔥 KEV endpoint General ⚡ nuclei
10.0
CRITICAL
EPSS
76.7%
2025 CWE-89 12 PoCs

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CVE-2025-34027
Concerto General ⚡ nuclei
10.0
CRITICAL
EPSS
2.8%
2025 CWE-367 1 PoC

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an unauthenticated actor to achieve remote code execution (RCE).This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

CVE-2025-45854
JEHC-BPM General ⚡ nuclei
10.0
CRITICAL
EPSS
21.4%
2025 CWE-862 0 PoCs

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

CVE-2025-31324
🔥 KEV SAP NetWeaver (Visual Composer development server) General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2025 CWE-434 20 PoCs

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVE-2020-6207
🔥 KEV SAP Solution Manager (User Experience Monitoring) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.2%
2020 6 PoCs

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

CVE-2020-6287
🔥 KEV SAP NetWeaver AS JAVA (LM Configuration Wizard) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2020 8 PoCs

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVE-2018-19276
Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.3%
2018 5 PoCs

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

CVE-2022-27593
🔥 KEV Photo Station General ⚡ nuclei
10.0
CRITICAL
EPSS
93.1%
2022 CWE-610 0 PoCs

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2023-48777
Elementor Website Builder General ⚡ nuclei
9.9
CRITICAL
EPSS
88.8%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.