38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-11549
W12 Web
8.7
HIGH
EPSS
0.6%
2025 CWE-121 1 PoC

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

CVE-2021-47795
GeoVision Geowebserver Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

CVE-2025-4983
City Referential Manager Web
8.7
HIGH
EPSS
0.2%
2025 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2025-7054
quiche Web Cloud
8.7
HIGH
EPSS
0.1%
2025 CWE-835 2 PoCs

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5.1 . Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers. An una

CVE-2025-9245
RE6250 Web
8.7
HIGH
EPSS
0.3%
2025 CWE-121 1 PoC

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function WPSSTAPINEnr of the file /goform/WPSSTAPINEnr. Performing manipulation of the argument ssid results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2017-20220
Serviio PRO Web
8.7
HIGH
EPSS
0.2%
2017 CWE-306 3 PoCs

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.

CVE-2023-53971
WebTareas Web
8.7
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVE-2024-7736
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.7%
2024 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2021-47726
NuCom 11N Wireless Router Web Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode the admin password in Base64 format.

CVE-2024-13982
SPON IP Network Broadcast System Web
8.7
HIGH
EPSS
2.4%
2024 CWE-22 1 PoC

SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory traversal and access sensitive files on the server. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted POST request to read arbitrary files, potentially exposing system configuration, credentials, or internal logic. An affected version range is undefi

CVE-2022-50936
WBCE CMS Web
8.7
HIGH
EPSS
0.9%
2022 CWE-434 1 PoC

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.

CVE-2025-0829
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
0.4%
2025 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2025-5848
AC15 Web
8.7
HIGH
EPSS
0.6%
2025 CWE-120 1 PoC

A vulnerability was found in Tenda AC15 15.03.05.19_multi and classified as critical. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. The manipulation of the argument list leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-6137
T10 Web
8.7
HIGH
EPSS
1.0%
2025 CWE-120 1 PoC

A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2020-37023
Koken CMS Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVE-2023-53924
Ulicms Web
8.7
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously crafted avatar uploads.

CVE-2020-37090
School ERP Pro Web
8.7
HIGH
EPSS
1.0%
2020 CWE-434 1 PoC

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

CVE-2023-53952
Dotclear Web
8.7
HIGH
EPSS
0.9%
2023 CWE-434 1 PoC

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the uploaded file is accessed, enabling arbitrary code execution on the server.

CVE-2021-47704
OpenBMCS Web Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 2 PoCs

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

CVE-2021-47749
YouPHPTube Web
8.7
HIGH
EPSS
0.2%
2021 CWE-22 1 PoC

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.