4 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2026-23550
Modular DS General ⚡ nuclei
10.0
CRITICAL
EPSS
4.8%
2026 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

CVE-2026-28409
WeGIA General ⚡ nuclei
10.0
CRITICAL
EPSS
1.4%
2026 CWE-78 0 PoCs

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

CVE-2026-41940
🔥 KEV cPanel General ⚡ nuclei
9.3
CRITICAL
EPSS
67.0%
2026 CWE-306 1 PoC

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

CVE-2026-25616
Blesta General ⚡ nuclei
4.7
MEDIUM
EPSS
2.5%
2026 CWE-79 1 PoC

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.