40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-56249
WPMasterToolKit General
9.1
CRITICAL
EPSS
41.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.

CVE-2020-26808
SAP AS ABAP(DMIS) General
9.1
CRITICAL
EPSS
3.7%
2020 2 PoCs

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

CVE-2025-10890
Chrome General
9.1
CRITICAL
EPSS
0.1%
2025 CWE-1300 1 PoC

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2020-12506
750-362 General
9.1
CRITICAL
EPSS
0.3%
2020 CWE-306 1 PoC

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.

CVE-2023-5832
mintplex-labs/anything-llm General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

CVE-2019-11857
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2019 1 PoC

Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

CVE-2024-6584
Jetpack Boost General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.

CVE-2023-29519
xwiki-platform General
9.1
CRITICAL
EPSS
4.7%
2023 CWE-74 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the vulnerability does not impact comments of a wiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.2, 15.0-rc-1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-1721
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-434 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2020-26820
SAP NetWeaver AS JAVA General
9.1
CRITICAL
EPSS
3.2%
2020 1 PoC

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.

CVE-2025-54576
oauth2-proxy General
9.1
CRITICAL
EPSS
0.2%
2025 CWE-290 1 PoC

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when using the skip_auth_routes configuration option with regex patterns. Attackers can bypass authentication by crafting URLs with query parameters that satisfy configured regex patterns, allowing unauthorized access to protected resources. The issue stems from skip_auth_routes matching against the full request URI. Deployments using skip_auth_routes

CVE-2024-20720
Adobe Commerce General
9.1
CRITICAL
EPSS
7.2%
2024 CWE-78 1 PoC

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

CVE-2023-47873
WP Child Theme Generator General ⚡ nuclei
9.1
CRITICAL
EPSS
13.0%
2023 CWE-434 0 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

CVE-2025-46117
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2025 1 PoC

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

CVE-2023-29534
Firefox for Android General
9.1
CRITICAL
EPSS
0.5%
2023 5 PoCs

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVE-2020-1731
keycloak General
9.1
CRITICAL
EPSS
0.4%
2020 CWE-341 1 PoC

A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

CVE-2020-7378
OpenCRX General
9.1
CRITICAL
EPSS
8.7%
2020 CWE-620 2 PoCs

CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to the affected OpenCRX instance can change the password of any user, including admin-Standard, to any chosen value. This issue was resolved in version 5.0-20200904, released September 4, 2020.

CVE-2020-36561
github.com/yi-ge/unzip General
9.1
CRITICAL
EPSS
0.6%
2020 1 PoC

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

CVE-2024-31345
Auto Poster General
9.1
CRITICAL
EPSS
1.3%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.