38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2016-0752
🔥 KEV Software Genérico Web
7.5
HIGH
EPSS
91.1%
2016 3 PoCs

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CVE-2025-41249
Spring Framework Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248

CVE-2016-8718
AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client Web
7.5
HIGH
EPSS
0.2%
2016 1 PoC

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.

CVE-2016-8723
AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client Web
7.5
HIGH
EPSS
0.4%
2016 2 PoCs

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

CVE-2023-3154
WordPress Gallery Plugin Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

CVE-2023-0678
phpipam/phpipam Web ⚡ nuclei
7.5
HIGH
EPSS
67.6%
2023 CWE-862 0 PoCs

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2025-65518
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.

CVE-2023-4279
User Activity Log Web Windows
7.5
HIGH
EPSS
2.1%
2023 2 PoCs

This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-27179
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
85.8%
2023 1 PoC

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVE-2023-21514
Galaxy Store Web
7.5
HIGH
EPSS
0.2%
2023 CWE-20 1 PoC

Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

CVE-2023-30800
RouterOS Web Networking
7.5
HIGH
EPSS
4.5%
2023 CWE-787 4 PoCs

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

CVE-2023-3604
Change WP Admin Login Web Windows
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

CVE-2022-1442
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
74.9%
2022 CWE-862 1 PoC

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

CVE-2016-8726
AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client Web
7.5
HIGH
EPSS
0.4%
2016 2 PoCs

An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.

CVE-2024-47917
CCTV FW Web
7.5
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2025-22963
Teedy Web
7.5
HIGH
EPSS
0.1%
2025 CWE-352 2 PoCs

Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.

CVE-2024-8700
Event Calendar Web Windows
7.5
HIGH
EPSS
0.5%
2024 1 PoC

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

CVE-2023-0215
OpenSSL Web
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then returns the new head of the BIO chain to the caller. Under certain conditions, for example if a CMS recipient public key is invalid, the new filter BIO is freed and the function returns a NULL result indica

CVE-2024-48939
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

CVE-2022-46355
SCALANCE X204RNA (HSR) Web
7.5
HIGH
EPSS
0.4%
2022 CWE-200 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products are vulnerable to an "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability by leaking sensitive data in the HTTP Referer.