5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-39946
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVE-2021-47850
Mini Mouse Web
8.7
HIGH
EPSS
0.3%
2021 CWE-22 1 PoC

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.

CVE-2021-4465
ReQuest Serious Play Pro Web
8.7
HIGH
EPSS
0.6%
2021 CWE-400 2 PoCs

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption of service availability.

CVE-2021-47749
YouPHPTube Web
8.7
HIGH
EPSS
0.2%
2021 CWE-22 1 PoC

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.

CVE-2021-47726
NuCom 11N Wireless Router Web Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode the admin password in Base64 format.

CVE-2021-4469
SHO-110 Web
8.7
HIGH
EPSS
0.3%
2021 CWE-306 1 PoC

Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote attacker to retrieve image snapshots by directly requesting the 'snapshot' endpoint. An attacker can repeatedly collect snapshots and reconstruct the camera stream, compromising the confidentiality of the monitored environment.

CVE-2021-47758
Chikitsa Patient Management System Web
8.7
HIGH
EPSS
0.7%
2021 CWE-434 1 PoC

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution on the server through a weaponized PHP script.

CVE-2021-22241
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

CVE-2021-47752
AWebServer GhostBuilding DevOps Web Database
8.7
HIGH
EPSS
0.3%
2021 CWE-770 1 PoC

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.

CVE-2021-47718
OpenBMCS Web
8.7
HIGH
EPSS
0.3%
2021 CWE-548 2 PoCs

OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.

CVE-2021-47757
Chikitsa Patient Management System Web
8.7
HIGH
EPSS
0.6%
2021 CWE-434 1 PoC

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.

CVE-2021-36800
Akaunting Web
8.7
HIGH
EPSS
0.3%
2021 CWE-94 1 PoC

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

CVE-2017-20220
Serviio PRO Web
8.7
HIGH
EPSS
0.2%
2017 CWE-306 3 PoCs

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.

CVE-2017-20212
FLIR Thermal Camera F/FC/PT/D Web
8.7
HIGH
EPSS
0.4%
2017 CWE-22 2 PoCs

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.

CVE-2017-20217
Serviio PRO Web
8.7
HIGH
EPSS
0.1%
2017 CWE-306 3 PoCs

Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows unauthenticated attackers to access sensitive information. Remote attackers can send specially crafted requests to the REST API endpoints to retrieve potentially sensitive configuration data without authentication.

CVE-2012-10056
PHP Volunteer Management Web
8.7
HIGH
EPSS
36.8%
2012 CWE-434 3 PoCs

PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely. The application ships with default credentials, making exploitation trivial. Once authenticated, the attacker can upload a PHP shell and trigger it via a direct GET request.

CVE-2012-10032
Maxthon3 Browser Web
8.7
HIGH
EPSS
48.6%
2012 CWE-79 3 PoCs

Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw enables modification of browser configuration and execution of arbitrary code through Maxthon’s exposed DOM APIs, including maxthon.program.Program.launch() and maxthon.io.writeDataURL(). Exploitation requires user interaction, typically by visiting a malicious webpage that triggers the injection.

CVE-2012-10061
Music Host Server Web
8.7
HIGH
EPSS
55.6%
2012 CWE-22 3 PoCs

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

CVE-2012-10042
Sflog! CMS Web
8.7
HIGH
EPSS
47.6%
2012 CWE-434 3 PoCs

Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uploaded, the file can be executed remotely, resulting in full remote code execution.

CVE-2012-10062
XAMPP Web
8.7
HIGH
EPSS
61.8%
2012 CWE-434 2 PoCs

A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resulting in remote code execution on the server.