38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-59932
flagForge Web
8.6
HIGH
EPSS
0.1%
2025 CWE-284 1 PoC

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.

CVE-2021-44388
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Login param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47778
My SMTP Contact Plugin Web
8.6
HIGH
EPSS
1.1%
2021 CWE-94 1 PoC

GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.

CVE-2025-13417
Plugin Organizer Web Database Windows
8.6
HIGH
EPSS
0.1%
2025 1 PoC

The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks.

CVE-2025-8085
Ditty Web Windows ⚡ nuclei
8.6
HIGH
EPSS
10.9%
2025 1 PoC

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

CVE-2021-44405
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. StartZoomFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-14824
Financial Services Analytical Applications Infrastructure Web Database
8.6
HIGH
EPSS
1.1%
2020 1 PoC

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. While the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in un

CVE-2021-47746
NodeBB Plugin Emoji Web
8.6
HIGH
EPSS
0.1%
2021 CWE-73 1 PoC

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.

CVE-2021-44379
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetAutoMaint param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44398
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=stop param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2023-0309
thorsten/phpmyfaq Web
8.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2021-44362
Software Genérico Web Cloud
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCloudSchedule param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2026-1505
DIR-615 Web
8.6
HIGH
EPSS
0.7%
2026 CWE-78 1 PoC

A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2021-36916
Hide My WP (WordPress plugin) Web Database Windows
8.6
HIGH
EPSS
0.6%
2021 CWE-89 1 PoC

The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible.

CVE-2021-44365
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetDevName param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44366
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-36901
UBICOD Medivision Digital Signage Web
8.6
HIGH
EPSS
0.1%
2020 CWE-352 2 PoCs

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with elevated privileges.

CVE-2021-44399
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetPtzPreset param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2026-3830
Product Filter for WooCommerce by WBW Web Database Windows
8.6
HIGH
EPSS
0.1%
2026 1 PoC

The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2022-25354
set-in Web
8.6
HIGH
EPSS
0.7%
2022 2 PoCs

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)