13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2026-35029
litellm Web ⚡ nuclei
8.7
HIGH
EPSS
14.9%
2026 CWE-863 1 PoC

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables, register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution, read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image, and take over other privileged accounts by overwriting UI_USERNAME and UI_PASSWORD

CVE-2026-40040
Pachno Web
8.7
HIGH
EPSS
0.1%
2026 CWE-434 1 PoC

Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them to achieve remote code execution on the server.

CVE-2026-2877
A18 Web
8.7
HIGH
EPSS
0.1%
2026 CWE-121 1 PoC

A vulnerability has been found in Tenda A18 15.13.07.13. This affects the function strcpy of the file /goform/WifiExtraSet of the component Httpd Service. The manipulation of the argument wpapsk_crypto5g leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-22787
html2pdf.js Web
8.7
HIGH
EPSS
0.0%
2026 CWE-79 1 PoC

html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts to be run on the client browser and risking the confidentiality, integrity, and availability of the page's data. This vulnerability has been fixed in html2pdf.js@0.14.0.

CVE-2026-24477
anything-llm Web ⚡ nuclei
8.7
HIGH
EPSS
11.2%
2026 CWE-201 0 PoCs

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with an API key, this QdrantApiKey could be exposed in plain text to unauthenticated users via the `/api/setup-complete` endpoint. Leakage of QdrantApiKey allows an unauthenticated attacker full read/write access to the Qdrant vector database instance used by AnythingLLM. Since Qdrant often stores the core knowledge base for RAG in AnythingLLM, this can lead to complete compromise of

CVE-2026-32596
glances Web ⚡ nuclei
8.7
HIGH
EPSS
5.2%
2026 CWE-200 0 PoCs

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys, tokens) to any network client. Version 4.5.2 fixes the issue.

CVE-2026-30796
RustDesk Server Pro Web Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source — API endpoint handling heartbeat sync and program routines Heartbeat API handler (accepts preset-address-book-password in plaintext). This issue affects RustDesk Server Pro: through 1.7.5.

CVE-2026-30795
RustDesk Client Web Windows
8.7
HIGH
EPSS
0.0%
2026 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines Heartbeat JSON payload construction (preset-address-book-password). This issue affects RustDesk Client: through 1.4.5.

CVE-2023-53933
Serendipity Web
8.7
HIGH
EPSS
0.8%
2023 CWE-434 1 PoC

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server.

CVE-2023-0050
GitLab DevOps Web
8.7
HIGH
EPSS
59.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.

CVE-2023-31223
Software Genérico Web
8.7
HIGH
EPSS
0.4%
2023 2 PoCs

Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.

CVE-2023-53921
SitemagicCMS Web
8.7
HIGH
EPSS
0.6%
2023 CWE-434 1 PoC

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

CVE-2023-26222
TIBCO EBX Web
8.7
HIGH
EPSS
0.4%
2023 1 PoC

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.

CVE-2023-53952
Dotclear Web
8.7
HIGH
EPSS
0.9%
2023 CWE-434 1 PoC

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the uploaded file is accessed, enabling arbitrary code execution on the server.

CVE-2023-53924
Ulicms Web
8.7
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.

CVE-2023-53971
WebTareas Web
8.7
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVE-2023-53970
Screen SFT DAB 600/C Web
8.7
HIGH
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted POST requests with manipulated session parameters.

CVE-2023-53917
Affiliate Me Web Database
8.7
HIGH
EPSS
0.0%
2023 CWE-89 1 PoC

Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint that allows authenticated administrators to manipulate database queries. Attackers can exploit the 'id' parameter with crafted union-based queries to extract sensitive user information including usernames and password hashes.

CVE-2023-53868
coppermine-gallery Web
8.7
HIGH
EPSS
0.6%
2023 CWE-434 1 PoC

Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.

CVE-2023-53980
projectSend Web
8.7
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server.