38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-34833
Software Genérico Web
9.8
CRITICAL
EPSS
42.1%
2024 2 PoCs

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

CVE-2026-33032
nginx-ui Web ⚡ nuclei
9.8
CRITICAL
EPSS
14.3%
2026 CWE-306 1 PoC

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering

CVE-2024-42815
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

CVE-2026-6951
simple-git Web
9.8
CRITICAL
EPSS
0.1%
2026 CWE-94 2 PoCs

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

CVE-2017-2891
Mongoose Web
9.8
CRITICAL
EPSS
2.9%
2017 1 PoC

An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.

CVE-2021-32122
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before 1.0.0.44.

CVE-2024-31848
API Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2024 CWE-22 2 PoCs

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

CVE-2021-4449
ZoomSounds - WordPress Wave Audio Player with Playlist Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.8%
2021 CWE-434 1 PoC

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this.

CVE-2024-21534
jsonpath-plus Web
9.8
CRITICAL
EPSS
92.7%
2024 CWE-94 5 PoCs

All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).

CVE-2019-25141
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2019 CWE-862 1 PoC

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

CVE-2024-4323
Fluent Bit Web
9.8
CRITICAL
EPSS
84.6%
2024 CWE-122 4 PoCs

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

CVE-2024-10441
DiskStation Manager (DSM) Web
9.8
CRITICAL
EPSS
1.9%
2024 CWE-116 1 PoC

Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2024-1981
Migration, Backup, Staging – WPvivid Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-42640
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.8%
2024 3 PoCs

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution on the server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-41617
Software Genérico Web
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.

CVE-2026-1615
jsonpath Web
9.8
CRITICAL
EPSS
0.1%
2026 CWE-94 2 PoCs

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects,

CVE-2024-12252
SEO LAT Auto Post Web Windows
9.8
CRITICAL
EPSS
66.5%
2024 CWE-94 2 PoCs

The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the seo-beginner-auto-post.php file which can be leveraged to achieve remote code execution.

CVE-2024-44849
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2024 1 PoC

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

CVE-2023-38035
🔥 KEV MobileIron Sentry Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 4 PoCs

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

CVE-2021-34621
ProfilePress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2021 CWE-269 4 PoCs

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .