38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-26223
spree Web
7.7
HIGH
EPSS
0.3%
2020 CWE-863 1 PoC

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is patched in versions 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.

CVE-2023-39421
IRM Next Generation Web Windows
7.7
HIGH
EPSS
0.1%
2023 CWE-798 1 PoC

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

CVE-2021-21918
Advantech Web Database
7.7
HIGH
EPSS
1.3%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack.

CVE-2021-21919
Advantech Web Database
7.7
HIGH
EPSS
1.3%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack.

CVE-2022-0427
GitLab DevOps Web
7.7
HIGH
EPSS
0.1%
2022 1 PoC

Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

CVE-2018-7340
Duo Network Gateway Web
7.7
HIGH
EPSS
0.1%
2018 CWE-287 2 PoCs

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

CVE-2021-21928
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-35653
Hyperion Essbase Administration Services Web Database
7.7
HIGH
EPSS
0.4%
2021 1 PoC

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Essbase Administration Services ac

CVE-2021-21917
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2024-31210
wordpress-develop Web Windows
7.7
HIGH
EPSS
1.0%
2024 CWE-434 1 PoC

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, th

CVE-2023-0098
Simple URLs Web Database Windows
7.7
HIGH
EPSS
0.7%
2023 1 PoC

The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.

CVE-2021-21923
Advantech Web Database
7.7
HIGH
EPSS
1.3%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.

CVE-2020-13550
Advantech Web
7.7
HIGH
EPSS
0.3%
2020 CWE-22 1 PoC

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

CVE-2025-10635
Find Me On Web Database Windows
7.7
HIGH
EPSS
0.0%
2025 1 PoC

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

CVE-2017-2829
Indoor IP Camera C1 Series Web
7.7
HIGH
EPSS
5.4%
2017 1 PoC

An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an attacker to specify a file outside of a directory. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

CVE-2021-21934
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

CVE-2017-11430
OmnitAuth-SAML Web
7.7
HIGH
EPSS
0.4%
2017 CWE-287 2 PoCs

OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

CVE-2023-0262
WP Airbnb Review Slider Web Database Windows
7.7
HIGH
EPSS
0.5%
2023 1 PoC

The WP Airbnb Review Slider WordPress plugin before 3.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2021-21927
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘loc_filter’ parameter.

CVE-2017-11429
saml2-js Web
7.7
HIGH
EPSS
0.3%
2017 CWE-287 2 PoCs

Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.