38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-30061
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

CVE-2019-1653
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2019 CWE-284 17 PoCs

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability.

CVE-2023-21857
HCM Common Architecture Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/

CVE-2025-50494
Software Genérico Web
7.5
HIGH
EPSS
0.2%
2025 1 PoC

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

CVE-2022-32574
iota All-In-One Security Kit Web
7.5
HIGH
EPSS
1.4%
2022 CWE-415 1 PoC

A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2018-0296
🔥 KEV Cisco Adaptive Security Appliance unknown Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2018 CWE-20 6 PoCs

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affec

CVE-2025-41249
Spring Framework Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248

CVE-2020-26073
Cisco Catalyst SD-WAN Manager Web Networking ⚡ nuclei
7.5
HIGH
EPSS
90.9%
2020 CWE-35 0 PoCs

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or

CVE-2018-12413
TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition Web
7.5
HIGH
EPSS
0.2%
2018 2 PoCs

The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition: 1.0.0, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition: 1.0.0.

CVE-2024-45254
VaeMendis Ubooquity version 2.1.2 Web
7.5
HIGH
EPSS
0.3%
2024 CWE-79 1 PoC

VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2025-65518
Software Genérico Web
7.5
HIGH
EPSS
0.0%
2025 1 PoC

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service unavailable to legitimate users. An attacker can exploit this issue remotely without authentication, resulting in a persistent availability impact on the affected Plesk Obsidian instance.

CVE-2025-62771
M6a Web
7.5
HIGH
EPSS
0.0%
2025 CWE-352 1 PoC

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

CVE-2023-29517
xwiki-platform Web
7.5
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet engine (e.g. tomcat) running XWiki. The same vulnerability also allowed to perform internal requests to resources from the hosting server. The problem has been patched in XWiki 13.10.11, 14.10.1, 14.4.8, 15.0-rc-1. Users are advised to upgrade. It might be possible to workaround th

CVE-2023-6271
Backup Migration Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

CVE-2021-31345
Capital Embedded AR Classic 431-422 Web
7.5
HIGH
EPSS
1.2%
2021 CWE-1284 1 PoC

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on a user-defined applications that runs on top of the UDP protocol. (FSMD-2021-0006)

CVE-2022-21567
Workflow Web Database
7.5
HIGH
EPSS
1.8%
2022 1 PoC

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2025-1323
WP-Recall – Registration, Profile, Commerce & More Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
27.3%
2025 CWE-89 1 PoC

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2021-21441
((OTRS)) Community Edition Web
7.5
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

There is a XSS vulnerability in the ticket overview screens. It's possible to collect various information by having an e-mail shown in the overview screen. Attack can be performed by sending specially crafted e-mail to the system and it doesn't require any user intraction. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions.

CVE-2025-8422
Propovoice: All-in-One Client Management System Web Windows
7.5
HIGH
EPSS
0.1%
2025 CWE-73 1 PoC

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.