38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-22786
ElementInvader Addons for Elementor Web
7.5
HIGH
EPSS
0.3%
2025 CWE-35 1 PoC

Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.2.6.

CVE-2023-52356
Software Genérico Web
7.5
HIGH
EPSS
0.7%
2023 CWE-122 5 PoCs

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

CVE-2021-20990
Fibaro Home Center Web
7.5
HIGH
EPSS
1.8%
2021 CWE-306 3 PoCs

In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recovery mode.

CVE-2022-4550
User Activity Web Windows
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

CVE-2020-36696
Product Input Fields for WooCommerce Web Windows
7.5
HIGH
EPSS
0.4%
2020 CWE-285 1 PoC

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

CVE-2024-57452
Software Genérico Web
7.5
HIGH
EPSS
0.2%
2024 1 PoC

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

CVE-2018-3906
SmartThings Hub STH-ETH-250 Web Database
7.5
HIGH
EPSS
0.1%
2018 1 PoC

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTTP server of Samsung SmartThings Hub. The video-core process insecurely extracts the shard.videoHostURL field from its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2023-2916
InfiniteWP Client Web Windows
7.5
HIGH
EPSS
29.5%
2023 CWE-200 1 PoC

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

CVE-2024-21274
Oracle WebLogic Server Web Database
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2019-9512
Software Genérico Web
7.5
HIGH
EPSS
51.2%
2019 CWE-400 3 PoCs

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVE-2021-22946
https://github.com/curl/curl Web
7.5
HIGH
EPSS
0.1%
2021 CWE-325 4 PoCs

A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw would then make curl silently continue its operations **withoutTLS** contrary to the instructions and expectations, exposing possibly sensitive data in clear text over the network.

CVE-2020-12512
Comtrol IO-Link Master Web
7.5
HIGH
EPSS
0.7%
2020 CWE-79 1 PoC

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

CVE-2025-63667
Software Genérico Web
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.

CVE-2020-13270
GitLab DevOps Web
7.5
HIGH
EPSS
0.4%
2020 1 PoC

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVE-2019-1653
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2019 CWE-284 17 PoCs

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

CVE-2023-5133
user-activity-log-pro Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-38039
curl Web
7.5
HIGH
EPSS
12.3%
2023 1 PoC

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2024-12812
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.

CVE-2023-6266
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
7.5
HIGH
EPSS
26.8%
2023 CWE-200 0 PoCs

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which can contain sensitive information such as user passwords, PII, database credentials, and much more.

CVE-2023-38950
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
83.4%
2023 0 PoCs

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.