38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6595
WhatsUp Gold Web
7.5
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

CVE-2025-11855
age-restriction Web Windows
7.5
HIGH
EPSS
0.0%
2025 1 PoC

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

CVE-2023-21854
Sales Offline Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2024-3475
Sticky Buttons Web Windows
7.5
HIGH
EPSS
0.1%
2024 1 PoC

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2021-40655
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2021 1 PoC

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CVE-2021-31233
Software Genérico Web Database
7.5
HIGH
EPSS
0.3%
2021 2 PoCs

SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter.

CVE-2016-0752
🔥 KEV Software Genérico Web
7.5
HIGH
EPSS
91.1%
2016 3 PoCs

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CVE-2023-31059
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2023 1 PoC

Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.

CVE-2019-1653
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2019 CWE-284 17 PoCs

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

CVE-2019-9512
Software Genérico Web
7.5
HIGH
EPSS
51.2%
2019 CWE-400 3 PoCs

Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVE-2022-30114
Software Genérico Web
7.5
HIGH
EPSS
4.8%
2022 2 PoCs

A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS.

CVE-2023-6021
ray-project/ray Web ⚡ nuclei
7.5
HIGH
EPSS
87.3%
2023 CWE-29 2 PoCs

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

CVE-2024-45293
PhpSpreadsheet Web ⚡ nuclei
7.5
HIGH
EPSS
70.3%
2024 CWE-611 0 PoCs

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files and sensitive information can be disclosed by providing a crafted sheet. The security scan function in src/PhpSpreadsheet/Reader/Security/XmlScanner.php contains a flawed XML encoding check to retrieve the input file's XML encoding in the toUtf8 function. The function searches

CVE-2023-26031
Apache Hadoop DevOps Web
7.5
HIGH
EPSS
9.3%
2023 CWE-426 3 PoCs

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop 3.3.0 updated the " YARN Secure Containers https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/SecureContainer.html " to add a feature for executing user-submitted applications in isolated linux containers. The native binary HADOOP_HOME/bin/container-executor is used to launch these containers; it must b

CVE-2018-12412
TIBCO FTL - Community Edition Web
7.5
HIGH
EPSS
0.1%
2018 1 PoC

The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO FTL - Community Edition: versions up to and including 5.4.0, TIBCO FTL - Developer Edition: versions up to and including 5.4.0, TIBCO FTL - Enterprise Edition: versions up to and including 5.4.0.

CVE-2023-4703
All in One B2B for WooCommerce Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

CVE-2022-25940
lite-server Web
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

CVE-2023-31594
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

CVE-2025-22963
Teedy Web
7.5
HIGH
EPSS
0.1%
2025 CWE-352 2 PoCs

Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.

CVE-2021-21441
((OTRS)) Community Edition Web
7.5
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions.