38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-29631
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

CVE-2023-30185
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2023 2 PoCs

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

CVE-2023-5877
affiliate-toolkit Web Windows
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

CVE-2024-7314
AJ-Report Web ⚡ nuclei
9.8
CRITICAL
EPSS
70.1%
2024 CWE-288 0 PoCs

anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

CVE-2023-34755
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

CVE-2025-70457
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2025 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

CVE-2026-30993
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2026 1 PoC

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

CVE-2025-5947
Service Finder Bookings Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
43.8%
2025 CWE-639 4 PoCs

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it possible for unauthenticated attackers to login as any user including admins.

CVE-2024-56828
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is parsed. For example, given a string like: data:image/html;base64,PGh0bWw+PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPjwvaHRtbD4= the content after the comma is extracted and decoded using Base64.getDecoder().decode(). The substring from the 11th character up to the first occurrence of a s

CVE-2025-65656
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

CVE-2024-37393
Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2024 3 PoCs

Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against the DESKTOP service exposed on the /secserver HTTP endpoint. This may include ms-Mcs-AdmPwd, which has a cleartext password for the Local Administrator Password Solution (LAPS) feature.

CVE-2024-54676
Apache OpenMeetings Web
9.8
CRITICAL
EPSS
6.1%
2024 CWE-502 1 PoC

Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data. Users are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.

CVE-2023-24199
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

CVE-2023-41506
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2024-4883
WhatsUp Gold Web
9.8
CRITICAL
EPSS
92.2%
2024 CWE-77 1 PoC

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

CVE-2023-6875
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2023 CWE-639 5 PoCs

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to reset the API key used to authenticate to the mailer and view logs, including password reset emails, allowing site takeover. CVE-2023-52233 appears to be a duplicate of this issue.

CVE-2015-10138
Work The Flow File Upload Web Windows
9.8
CRITICAL
EPSS
67.5%
2015 CWE-434 1 PoC

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2023-4188
instantsoft/icms2 Web Database
9.8
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-1478
Hummingbird Web Windows
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.4%
2023 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.