38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-60574
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2025 1 PoC

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to properly sanitize user-supplied input. An attacker can exploit this by sending a crafted GET request to retrieve arbitrary files from the underlying system.

CVE-2023-30061
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

CVE-2023-21857
HCM Common Architecture Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/

CVE-2024-46982
next.js Web Networking
7.5
HIGH
EPSS
49.1%
2024 CWE-639 2 PoCs

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a `Cache-Control: s-maxage=1, stale-while-revalidate` header which some upstream CDNs may cache as well. To be potentially affected all of the following must apply: 1. Next.js between 13.5.1 and 14.2.9, 2. Using pages router, & 3. Using non-

CVE-2022-4158
Contest Gallery Web Database Windows
7.5
HIGH
EPSS
1.3%
2022 2 PoCs

The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database.

CVE-2024-47920
CMS Web
7.5
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-13322
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
21.5%
2024 CWE-89 0 PoCs

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-2757
PHP Web
7.5
HIGH
EPSS
0.6%
2024 1 PoC

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.

CVE-2018-3914
SmartThings Hub STH-ETH-250 Web
7.5
HIGH
EPSS
0.2%
2018 2 PoCs

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 2000 bytes. An attacker can send an arbitrarily long "sessionToken" value in order to exploit this vulnerability.

CVE-2021-40655
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2021 1 PoC

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CVE-2019-5054
N300 WNR2000v5 Web
7.5
HIGH
EPSS
11.2%
2019 CWE-476 1 PoC

An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.

CVE-2024-12157
Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Web Database Windows
7.5
HIGH
EPSS
10.2%
2024 CWE-89 1 PoC

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2021-21975
🔥 KEV VMware vRealize Operations Web ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2021 6 PoCs

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

CVE-2023-29517
xwiki-platform Web
7.5
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet engine (e.g. tomcat) running XWiki. The same vulnerability also allowed to perform internal requests to resources from the hosting server. The problem has been patched in XWiki 13.10.11, 14.10.1, 14.4.8, 15.0-rc-1. Users are advised to upgrade. It might be possible to workaround th

CVE-2023-6271
Backup Migration Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

CVE-2025-11855
age-restriction Web Windows
7.5
HIGH
EPSS
0.0%
2025 1 PoC

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin user with a hardcoded username and arbitrary password.

CVE-2020-36696
Product Input Fields for WooCommerce Web Windows
7.5
HIGH
EPSS
0.4%
2020 CWE-285 1 PoC

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

CVE-2025-4138
CPython Web
7.5
HIGH
EPSS
0.3%
2025 CWE-22 1 PoC

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no fil

CVE-2020-7067
PHP Web
7.5
HIGH
EPSS
10.0%
2020 CWE-125 3 PoCs

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.