13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0838
hestiacp/hestiacp Web
6.6
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

CVE-2022-21210
lansweeper Web Database
6.6
MEDIUM
EPSS
6.7%
2022 CWE-89 2 PoCs

An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-0509
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-3294
Kubernetes DevOps Web
6.6
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server'

CVE-2022-2777
microweber/microweber Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

CVE-2022-21403
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2014-0207
Software Genérico Web
6.5
MEDIUM
EPSS
9.2%
2014 3 PoCs

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

CVE-2014-3478
Software Genérico Web
6.5
MEDIUM
EPSS
25.3%
2014 2 PoCs

Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

CVE-2014-3480
Software Genérico Web
6.5
MEDIUM
EPSS
8.1%
2014 3 PoCs

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

CVE-2026-1235
WP eCommerce Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2026-3098
Smart Slider 3 Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2026-0722
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Database Windows
6.5
MEDIUM
EPSS
0.0%
2026 CWE-89 1 PoC

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2026-3131
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-200 1 PoC

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.

CVE-2026-1710
WooPayments: Integrated WooCommerce Payments Web Windows
6.5
MEDIUM
EPSS
0.1%
2026 CWE-285 1 PoC

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.

CVE-2026-29905
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (DoS) via a malformed image upload. The application fails to properly validate the return value of the PHP getimagesize() function. When the system attempts to process this file for metadata or thumbnail generation, it triggers a fatal TypeError.

CVE-2026-6706
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

CVE-2026-4432
YITH WooCommerce Wishlist Web Windows
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible for unauthenticated attackers to rename any wishlist belonging to any user on the site.

CVE-2026-4927
Server Web
6.5
MEDIUM
EPSS
0.0%
2026 CWE-201 1 PoC

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

CVE-2026-1504
Chrome Web
6.5
MEDIUM
EPSS
0.0%
2026 1 PoC

Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVE-2026-30662
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2026 1 PoC

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/backend/file.php' improperly manages memory when creating zip archives. It uses 'ZipArchive::addFromString' combined with 'file_get_contents', which loads the entire content of every selected file into PHP memory. An authenticated attacker can exploit this by requesting a bulk download of large files, triggering an Out-Of-Memory (OOM) condition that causes the PHP-FPM process to terminate (SIGSEGV) and the web server to return a 500 error.