40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-8992
TIBCO ActiveMatrix BPM General
9.9
CRITICAL
EPSS
0.7%
2019 1 PoC

The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains a vulnerability wherein a user without privileges to upload distributed application archives ("Upload DAA" permission) can theoretically upload arbitrary code, an

CVE-2019-10758
🔥 KEV mongo-express General ⚡ nuclei
9.9
CRITICAL
EPSS
94.4%
2019 4 PoCs

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

CVE-2021-21466
SAP Business Warehouse General
9.9
CRITICAL
EPSS
2.5%
2021 2 PoCs

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.

CVE-2019-11510
🔥 KEV Software Genérico General ⚡ nuclei
9.9
CRITICAL
EPSS
94.5%
2019 12 PoCs

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVE-2019-5153
Moxa General
9.9
CRITICAL
EPSS
2.3%
2019 CWE-121 1 PoC

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVE-2019-5138
Moxa General
9.9
CRITICAL
EPSS
3.7%
2019 CWE-78 1 PoC

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

CVE-2024-42448
Service Provider Console General
9.9
CRITICAL
EPSS
64.4%
2024 2 PoCs

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CVE-2024-54262
Import Export For WooCommerce General
9.9
CRITICAL
EPSS
54.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.

CVE-2015-2079
Usermin General
9.9
CRITICAL
EPSS
2.8%
2015 CWE-96 1 PoC

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

CVE-2024-37762
Software Genérico General
9.9
CRITICAL
EPSS
28.0%
2024 1 PoC

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2026-22907
TDC-X401GL General
9.9
CRITICAL
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

CVE-2023-48777
Elementor Website Builder General ⚡ nuclei
9.9
CRITICAL
EPSS
88.8%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

CVE-2024-31286
WP Photo Album Plus General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

CVE-2024-31380
Oxygen Builder General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

CVE-2024-9014
pgAdmin 4 General ⚡ nuclei
9.9
CRITICAL
EPSS
92.9%
2024 2 PoCs

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

CVE-2024-25693
Portal for ArcGIS General
9.9
CRITICAL
EPSS
9.9%
2024 CWE-22 1 PoC

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

CVE-2024-4701
Genie General
9.9
CRITICAL
EPSS
17.6%
2024 CWE-22 2 PoCs

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

CVE-2024-50427
SurveyJS General
9.9
CRITICAL
EPSS
69.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

CVE-2024-52429
WP Quick Setup General
9.9
CRITICAL
EPSS
41.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.

CVE-2024-37361
Pentaho Data Integration & Analytics General
9.9
CRITICAL
EPSS
0.4%
2024 CWE-502 1 PoC

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to le