38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-0526
chatwoot/chatwoot Web
7.3
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.

CVE-2024-30983
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file.

CVE-2023-46870
Software Genérico Web
7.3
HIGH
EPSS
0.2%
2023 1 PoC

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.

CVE-2022-4805
usememos/memos Web
7.3
HIGH
EPSS
0.2%
2022 CWE-648 1 PoC

Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

CVE-2023-3672
plaidweb/webmention.js Web
7.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.

CVE-2017-20029
PHPList Web Database
7.3
HIGH
EPSS
1.8%
2017 CWE-89 2 PoCs

A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2022-2812
Guest Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-206398 is the identifier assigned to this vulnerability.

CVE-2023-4180
Free Hospital Management System for Small Practices Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file /vm/login.php. The manipulation of the argument useremail/userpassword leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236215.

CVE-2024-1035
openBI Web
7.3
HIGH
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252310 is the identifier assigned to this vulnerability.

CVE-2024-10958
WP Photo Album Plus Web Windows
7.3
HIGH
EPSS
55.7%
2024 CWE-94 1 PoC

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2017-20128
KB Messages PHP Script Web Database
7.3
HIGH
EPSS
0.3%
2017 CWE-89 2 PoCs

A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2020-36542
Demokratian Web
7.3
HIGH
EPSS
0.5%
2020 CWE-269 3 PoCs

A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2015-10063
TheRadSystem Web Database
7.3
HIGH
EPSS
0.1%
2015 CWE-89 1 PoC

A vulnerability was found in saemorris TheRadSystem and classified as critical. This issue affects the function redirect of the file _login.php. The manipulation of the argument user/pass leads to sql injection. The attack may be initiated remotely. The identifier of the patch is bfba26bd34af31648a11af35a0bb66f1948752a6. It is recommended to apply a patch to fix this issue. The identifier VDB-218453 was assigned to this vulnerability.

CVE-2022-2664
Private Cloud Management Platform Web Cloud
7.3
HIGH
EPSS
0.3%
2022 CWE-287 1 PoC

A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. VDB-205614 is the identifier assigned to this vulnerability.

CVE-2023-49968
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

CVE-2023-34035
Spring Security Web
7.3
HIGH
EPSS
2.5%
2023 2 PoCs

Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that maps HTTP endpoints to methods on @Controller-annotated classes.) Specifically, an application is vulnerable when all of the following are true: * Spring MVC is on the classpath * Spring Security is securing more than one servlet in a single application (one of them being

CVE-2021-22171
GitLab DevOps Web
7.3
HIGH
EPSS
0.1%
2021 1 PoC

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVE-2022-2802
Gas Agency Management System Web Database
7.3
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206248.

CVE-2023-4184
Inventory Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-236219.

CVE-2020-28458
datatables.net Web
7.3
HIGH
EPSS
1.2%
2020 2 PoCs

All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.