38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-9422
GEO my WP Web Windows
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2025-13070
CSV to SortTable Web Windows
6.6
MEDIUM
EPSS
0.1%
2025 1 PoC

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

CVE-2021-4175
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4139
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2021 CWE-79 1 PoC

pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2020-7336
Network Security Management (NSM) Web
6.6
MEDIUM
EPSS
0.2%
2020 CWE-352 1 PoC

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

CVE-2024-9529
Secure Custom Fields Web Windows
6.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

CVE-2025-65855
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identical across all devices and does not authenticate update servers or validate firmware signatures. An attacker with brief physical access can activate OTA mode (8-second button press), create a malicious WiFi AP using the known credentials, and serve malicious firmware via unauthenticated HTTP to achieve arbitrary code execution on this safety-critical emergency signaling device.

CVE-2025-44779
Software Genérico Web
6.6
MEDIUM
EPSS
0.0%
2025 1 PoC

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

CVE-2023-31493
Software Genérico Web
6.6
MEDIUM
EPSS
2.5%
2023 2 PoCs

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

CVE-2023-37941
Apache Superset Web
6.6
MEDIUM
EPSS
84.2%
2023 CWE-502 2 PoCs

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

CVE-2020-6114
Glacies IceHRM" Web Database
6.6
MEDIUM
EPSS
2.2%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-4116
yetiforcecompany/yetiforcecrm Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-21401
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-21403
Communications Operations Monitor Web Database
6.6
MEDIUM
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communicati

CVE-2022-2777
microweber/microweber Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.1.

CVE-2022-3294
Kubernetes DevOps Web
6.6
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server'

CVE-2022-0509
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-21210
lansweeper Web Database
6.6
MEDIUM
EPSS
6.7%
2022 CWE-89 2 PoCs

An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-0838
hestiacp/hestiacp Web
6.6
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.

CVE-2022-0285
pimcore/pimcore Web
6.6
MEDIUM
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.