1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2015-7450
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2015 1 PoC

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

CVE-2015-4852
🔥 KEV Software Genérico Web Database
9.8
CRITICAL
EPSS
92.9%
2015 10 PoCs

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

CVE-2015-10137
Website Contact Form With File Upload Web Windows
9.8
CRITICAL
EPSS
67.5%
2015 CWE-434 1 PoC

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2015-1635
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2015 32 PoCs

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

CVE-2015-10135
WPshop 2 – E-Commerce Web Windows
9.8
CRITICAL
EPSS
65.2%
2015 CWE-434 1 PoC

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2015-10138
Work The Flow File Upload Web Windows
9.8
CRITICAL
EPSS
67.5%
2015 CWE-434 1 PoC

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2026-1615
jsonpath Web
9.8
CRITICAL
EPSS
0.1%
2026 CWE-94 2 PoCs

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects,

CVE-2026-33032
nginx-ui Web ⚡ nuclei
9.8
CRITICAL
EPSS
14.3%
2026 CWE-306 1 PoC

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering

CVE-2026-26833
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2026 1 PoC

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

CVE-2026-2331
SICK Lector85x Web
9.8
CRITICAL
EPSS
0.1%
2026 CWE-552 1 PoC

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

CVE-2026-23744
inspector Web ⚡ nuclei
9.8
CRITICAL
EPSS
29.4%
2026 CWE-306 0 PoCs

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

CVE-2026-30993
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2026 1 PoC

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

CVE-2026-30694
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2026 2 PoCs

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

CVE-2026-2631
Datalogics Ecommerce Delivery Web Windows
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress `update_option()` operations. Attackers can use this to enable registartion and to set the default role as Administrator.

CVE-2026-27944
nginx-ui Web ⚡ nuclei
9.8
CRITICAL
EPSS
5.8%
2026 CWE-311 0 PoCs

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private keys, Nginx configurations) and decrypt it immediately. This issue has been patched in version 2.3.3.

CVE-2026-2446
PowerPack for LearnDash Web Windows
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

CVE-2026-29861
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2026 1 PoC

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

CVE-2026-6951
simple-git Web
9.8
CRITICAL
EPSS
0.1%
2026 CWE-94 2 PoCs

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

CVE-2026-20129
Cisco Catalyst SD-WAN Manager Web Networking
9.8
CRITICAL
EPSS
0.1%
2026 CWE-287 1 PoC

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by t

CVE-2023-5604
Asgaros Forum Web Windows
9.8
CRITICAL
EPSS
7.0%
2023 1 PoC

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.