13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-9529
Secure Custom Fields Web Windows
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

CVE-2024-9422
GEO my WP Web Windows
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2024-28224
Software Genérico Web
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

CVE-2024-0788
SUPERAntiSpyware Pro X Web
6.6
MEDIUM
EPSS
0.0%
2024 CWE-96 1 PoC

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver.

CVE-2021-4139
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4179
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4116
yetiforcecompany/yetiforcecrm Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4175
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2025-13070
CSV to SortTable Web Windows
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

CVE-2025-44779
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

CVE-2025-65855
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second button press), create a malicious WiFi AP using the known credentials, and serve malicious firmware via unauthenticated HTTP to achieve arbitrary code execution on this safety-critical emergency signaling device.

CVE-2020-6114
Glacies IceHRM" Web Database
6.6
MEDIUM
EPSS
2.2%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2020-7336
Network Security Management (NSM) Web
6.6
MEDIUM
EPSS
0.2%
2020 CWE-352 1 PoC

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

CVE-2018-2380
🔥 KEV SAP CRM Web
6.6
MEDIUM
EPSS
48.8%
2018 3 PoCs

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

CVE-2022-29170
grafana DevOps Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-601 1 PoC

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a p

CVE-2022-21399
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-21401
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-0341
vanessa219/vditor Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.

CVE-2022-0262
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.

CVE-2022-0285
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.