38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-25108
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_gre function with the remote_ip variable.

CVE-2022-3243
Import all XML, CSV & TXT into WordPress Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

CVE-2020-7328
MVISION Endpoint ePO extension Web
7.2
HIGH
EPSS
1.5%
2020 CWE-918 1 PoC

External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.

CVE-2022-4372
Web Invoice Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 2 PoCs

The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well

CVE-2019-2616
🔥 KEV BI Publisher (formerly XML Publisher) Web Database ⚡ nuclei
7.2
HIGH
EPSS
94.0%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI

CVE-2023-25119
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_pptp function with the remote_subnet and the remote_mask variables.

CVE-2022-3150
WP Custom Cursors | WordPress Cursor Plugin Web Database Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

CVE-2020-13125
Software Genérico Web Windows ⚡ nuclei
7.2
HIGH
EPSS
11.3%
2020 2 PoCs

An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

CVE-2023-50381
WBR-6013 Web
7.2
HIGH
EPSS
0.3%
2023 CWE-78 2 PoCs

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.

CVE-2023-43482
ER7206 Omada Gigabit VPN Router Web Networking
7.2
HIGH
EPSS
5.6%
2023 CWE-78 2 PoCs

A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2023-4221
Chamilo Web
7.2
HIGH
EPSS
1.9%
2023 CWE-78 1 PoC

Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.

CVE-2023-49909
AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) Web
7.2
HIGH
EPSS
0.9%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `action` parameter at offset `0x0045ab38` of the `httpd_portal` binary shipped with v5.1.0 Build 20220926 of the EAP225.

CVE-2023-25090
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the handle_interface_acl function with the interface and in_acl variables.

CVE-2025-54478
Mattermost Confluence Plugin Web
7.2
HIGH
EPSS
0.1%
2025 CWE-306 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.

CVE-2022-3394
WP All Export Pro Web Windows
7.2
HIGH
EPSS
1.3%
2022 CWE-94 1 PoC

The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbitrary code on the site. By default only administrators can run exports, but the privilege can be delegated to lower privileged users.

CVE-2023-26213
Software Genérico Web Cloud
7.2
HIGH
EPSS
3.9%
2023 2 PoCs

On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request allows an authenticated attacker to execute arbitrary commands. For example, a name field can contain :password and a password field can contain shell metacharacters.

CVE-2023-25094
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the into_class_node function with either the class_name or old_class_name variable.

CVE-2023-0277
WC Fields Factory Web Database Windows
7.2
HIGH
EPSS
0.5%
2023 1 PoC

The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-0924
ZYREX POPUP Web Windows
7.2
HIGH
EPSS
1.0%
2023 1 PoC

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install.

CVE-2023-52155
Software Genérico Web Database
7.2
HIGH
EPSS
0.4%
2023 1 PoC

A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.