38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2021-44419
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMdAlarm param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47735
Cmsimple Web
8.6
HIGH
EPSS
0.5%
2021 CWE-94 1 PoC

CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.

CVE-2021-44407
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestEmail param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44373
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetAutoFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44394
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2023-53958
LDAP Tool Box Self Service Password Web Windows
8.6
HIGH
EPSS
0.1%
2023 CWE-640 1 PoC

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

CVE-2021-44384
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetPtzTattern param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2025-3545
Magic NX15 Web
8.6
HIGH
EPSS
0.5%
2025 CWE-77 1 PoC

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CVE-2021-44364
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetWifi param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47736
CMSimple_XH Web
8.6
HIGH
EPSS
1.1%
2021 CWE-94 1 PoC

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVE-2021-2069
Outside In Technology Web Database
8.6
HIGH
EPSS
1.1%
2021 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that are affected are 8.5.4 and 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauth

CVE-2020-36900
Digital Signage System Web
8.6
HIGH
EPSS
0.0%
2020 CWE-352 2 PoCs

All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user with global administrative privileges when a logged-in user visits the page.

CVE-2025-34088
Pandora FMS Web
8.6
HIGH
EPSS
74.1%
2025 CWE-78 1 PoC

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performing network tools operations, such as pinging. This occurs because user input is not properly sanitized before being passed to system commands, enabling command injection.

CVE-2021-44361
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Set3G param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-2838
CRM Gateway for Mobile Devices Web Database
8.6
HIGH
EPSS
1.6%
2020 1 PoC

Vulnerability in the Oracle CRM Gateway for Mobile Devices product of Oracle E-Business Suite (component: Setup of Mobile Applications). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Gateway for Mobile Devices. While the vulnerability is in Oracle CRM Gateway for Mobile Devices, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Gateway

CVE-2012-10029
Nagios XI Graph Explorer Web
8.6
HIGH
EPSS
50.8%
2012 CWE-78 2 PoCs

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.

CVE-2021-47871
Hestia Control Panel Web Networking
8.6
HIGH
EPSS
0.1%
2021 CWE-73 1 PoC

Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific file paths on the server.

CVE-2021-44356
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2024-27453
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2024 1 PoC

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

CVE-2024-3826
Akana API Platform Web
8.6
HIGH
EPSS
0.2%
2024 CWE-287 1 PoC

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.