38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-36999
Elaniin CMS Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.

CVE-2019-25508
Hazir Ilan Sitesi Scripti Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Jettweb Php Hazir Ilan Sitesi Scripti V2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'kat' parameter. Attackers can send GET requests to the katgetir.php endpoint with malicious 'kat' values to extract sensitive database information.

CVE-2019-25439
NoviSmart CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field. Attackers can craft requests with time-based SQL injection payloads in the Referer header to extract sensitive database information or cause denial of service.

CVE-2019-25640
Inout Article Base CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.

CVE-2022-32774
Foxit Reader Web
8.8
HIGH
EPSS
0.5%
2022 CWE-416 1 PoC

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVE-2019-25496
osCommerce Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the products_id parameter. Attackers can modify the products_id value in product_info.php requests and append boolean-based SQL injection payloads to extract sensitive database information.

CVE-2014-6278
🔥 KEV Software Genérico Web Networking
8.8
HIGH
EPSS
91.4%
2014 10 PoCs

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and C

CVE-2020-37141
AMSS++ Web Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.

CVE-2026-40217
LiteLLM Web
8.8
HIGH
EPSS
0.2%
2026 CWE-420 1 PoC

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

CVE-2008-3938
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2008 1 PoC

Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.

CVE-2019-19979
Software Genérico Web Windows
8.8
HIGH
EPSS
0.2%
2019 2 PoCs

A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.

CVE-2026-41473
cyberpanel Web
8.8
HIGH
EPSS
0.7%
2026 CWE-306 1 PoC

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data.

CVE-2019-8991
TIBCO ActiveMatrix BPM Web
8.8
HIGH
EPSS
0.2%
2019 1 PoC

The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains multiple vulnerabilities that may allow for cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMa

CVE-2019-25636
Zeeways Jobsite CMS Web Database
8.8
HIGH
EPSS
0.1%
2019 CWE-89 1 PoC

Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET parameter. Attackers can send crafted requests to news_details.php, jobs_details.php, or job_cmp_details.php with malicious 'id' values using GROUP BY and CASE statements to extract sensitive database information.

CVE-2024-3643
Newsletter Popup Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack

CVE-2024-6022
ContentLock Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2021-3100
log4j-cve-2021-44228-hotpatch Web
8.8
HIGH
EPSS
0.0%
2021 CWE-250 1 PoC

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.

CVE-2024-39063
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.

CVE-2019-25523
XooGallery Web Database
8.8
HIGH
EPSS
0.2%
2019 CWE-89 1 PoC

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. Attackers can send GET requests to cat.php with malicious cat_id values to bypass authentication, extract sensitive data, or modify database contents.

CVE-2019-25532
Netartmedia Jobs Portal Web Database
8.8
HIGH
EPSS
0.3%
2019 CWE-89 1 PoC

Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sensitive database information or bypass authentication.