13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-8101
LifeShield DIY HD Video Doorbell Web
6.9
MEDIUM
EPSS
0.5%
2020 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.

CVE-2020-36922
Sony BRAVIA Digital Signage Web
6.9
MEDIUM
EPSS
0.2%
2020 CWE-497 2 PoCs

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.

CVE-2020-8493
Software Genérico Web
6.9
MEDIUM
EPSS
1.2%
2020 2 PoCs

A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

CVE-2020-36884
BrightSign Digital Signage Diagnostic Web Server Web Networking
6.9
MEDIUM
EPSS
0.1%
2020 CWE-918 2 PoCs

BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts.

CVE-2020-37156
BloodX Web
6.9
MEDIUM
EPSS
0.1%
2020 CWE-288 1 PoC

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access.

CVE-2016-20053
Redaxo CMS Web
6.9
MEDIUM
EPSS
0.0%
2016 CWE-352 1 PoC

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTML forms targeting the users endpoint with hidden fields containing admin credentials and account parameters to add new administrator accounts without user consent.

CVE-2016-20051
Snews CMS Cross Site Request Forgery Web
6.9
MEDIUM
EPSS
0.0%
2016 CWE-352 1 PoC

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup action, modifying the admin username and password parameters to gain unauthorized access.

CVE-2016-20035
Wowza Streaming Engine Web
6.9
MEDIUM
EPSS
0.1%
2016 CWE-352 2 PoCs

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.

CVE-2018-25174
ABC ERP Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-352 1 PoC

ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credentials by submitting forged requests to _configurar_perfil.php. Attackers can craft malicious forms or links containing parameters like usuario, contrasena1, contrasena2, nombre, and email to change admin account settings without authentication.

CVE-2018-25177
Data Center Audit Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-352 1 PoC

Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentication by submitting crafted POST requests. Attackers can send requests to dca_resetpw.php with parameters updateuser, pass, pass2, and submit_reset to change the admin account password and gain administrative access.

CVE-2018-25200
OOP CMS BLOG Web
6.9
MEDIUM
EPSS
0.1%
2018 CWE-352 1 PoC

OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to administrative privileges to gain unauthorized access.

CVE-2018-25298
Merge PACS Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-352 1 PoC

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system.

CVE-2018-25186
Tina4 Stack Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-352 1 PoC

Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credentials by submitting forged POST requests to the profile endpoint. Attackers can craft HTML forms targeting the /kim/profile endpoint with hidden fields containing malicious user data like passwords and email addresses to update administrator accounts without authentication.

CVE-2018-25214
MegaPing Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-787 1 PoC

MegaPing contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload to the Destination Address List field in the Finger function. Attackers can paste a crafted buffer exceeding expected input limits into the vulnerable field and trigger the Start button to cause a denial of service crash.

CVE-2018-25190
Easyndexer Web
6.9
MEDIUM
EPSS
0.0%
2018 CWE-352 1 PoC

Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitting forged POST requests. Attackers can craft malicious web pages that submit POST requests to createuser.php with parameters including username, password, name, surname, and privileges set to 1 for administrator access.

CVE-2018-25184
Surreal ToDo Web
6.9
MEDIUM
EPSS
0.1%
2018 CWE-22 1 PoC

Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter. Attackers can supply directory traversal sequences through the content parameter in index.php to access sensitive system files like configuration and initialization files.

CVE-2022-2589
beancount/fava Web
6.9
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.3.

CVE-2022-0967
star7th/showdoc Web
6.9
MEDIUM
EPSS
0.8%
2022 CWE-79 2 PoCs

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2026-8209
gibbon Web
6.9
MEDIUM
EPSS
0.0%
2026 CWE-23 1 PoC

Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher privileges. Exploitation could result in loss of availability of the web application.

CVE-2026-4908
Simple Laundry System Web Database
6.9
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.