38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-43687
TimeProvider 4100 Web
7.7
HIGH
EPSS
3.4%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-12015
WP Project Manager Web Database Windows
7.7
HIGH
EPSS
0.3%
2024 CWE-89 1 PoC

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

CVE-2021-21929
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21915
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21937
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21380
xwiki-platform Web Database
7.7
HIGH
EPSS
3.3%
2021 CWE-89 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments. This might lead to an SQL script injection quite easily for any user having Script rights on XWiki. The problem has been patched in XWiki 12.9RC1. The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.

CVE-2025-0107
Cloud NGFW Web Networking Cloud ⚡ nuclei
7.7
HIGH
EPSS
79.5%
2025 CWE-78 0 PoCs

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

CVE-2021-21234
spring-boot-actuator-logview Web ⚡ nuclei
7.7
HIGH
EPSS
93.9%
2021 CWE-22 2 PoCs

spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request parameters. While the filename parameter was checked to prevent directory traversal exploits (so that `file

CVE-2021-21924
Advantech Web Database
7.7
HIGH
EPSS
1.4%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

CVE-2024-6379
3DSwymer Web
7.7
HIGH
EPSS
1.0%
2024 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2021-21936
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-40405
RLC-410W Web
7.7
HIGH
EPSS
0.1%
2021 CWE-284 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-21926
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘health_filter’ parameter.

CVE-2021-28807
Q’center Web Cloud
7.7
HIGH
EPSS
0.9%
2021 CWE-79 2 PoCs

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later

CVE-2025-14804
Frontend File Manager Plugin Web Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server

CVE-2024-5585
PHP Web Windows
7.7
HIGH
EPSS
0.9%
2024 CWE-116 1 PoC

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

CVE-2021-21932
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21931
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2020-26223
spree Web
7.7
HIGH
EPSS
0.3%
2020 CWE-863 1 PoC

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

CVE-2018-7340
Duo Network Gateway Web
7.7
HIGH
EPSS
0.1%
2018 CWE-287 2 PoCs

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.