38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-8277
WooCommerce Photo Reviews Premium Web Windows
9.8
CRITICAL
EPSS
52.1%
2024 CWE-288 1 PoC

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly verifying the user's identity. This makes it possible for unauthenticated attackers to log in as user that has dismissed an admin notice in the past 30 days, which is often an administrator. Alternatively, a user can log in as any user with any transient that has a valid user_id as the value, though it would be more difficult t

CVE-2025-13374
Kalrav AI Agent Web Windows
9.8
CRITICAL
EPSS
0.1%
2025 CWE-434 2 PoCs

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-44812
Software Genérico Web Database
9.8
CRITICAL
EPSS
18.7%
2024 1 PoC

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

CVE-2024-40324
Software Genérico Web
9.8
CRITICAL
EPSS
12.0%
2024 1 PoC

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

CVE-2024-7456
lunary-ai/lunary Web Database
9.8
CRITICAL
EPSS
29.3%
2024 CWE-89 1 PoC

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

CVE-2023-41505
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2025-15030
User Profile Builder Web Windows
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

CVE-2024-43441
Apache HugeGraph-Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
90.4%
2024 CWE-302 0 PoCs

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.

CVE-2024-51064
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

CVE-2023-25076
SNIProxy Web
9.8
CRITICAL
EPSS
35.5%
2023 CWE-120 2 PoCs

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.

CVE-2025-7437
Ebook Store Web Windows
9.8
CRITICAL
EPSS
0.7%
2025 CWE-434 1 PoC

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2025-56513
Software Genérico Web
9.8
CRITICAL
EPSS
0.5%
2025 2 PoCs

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the update url and can hijack the update process and deliver arbitrary executables that are automatically executed, resulting in full remote code execution. This constitutes a critical supply chain attack vector. NOTE: the Supplier reports that the existence of an http://update.nicehash.com URL is a fabrication, and that there is no other use of HTTP (rather than HTTPS).

CVE-2024-6460
Grow by Tradedoubler Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 3 PoCs

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2024-45195
🔥 KEV Apache OFBiz Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2024 CWE-425 1 PoC

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVE-2023-49970
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

CVE-2024-32735
CyberPower PowerPanel Enterprise Web ⚡ nuclei
9.8
CRITICAL
EPSS
72.7%
2024 1 PoC

An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.

CVE-2013-2251
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2013 7 PoCs

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVE-2024-11068
DSL6740C Web Networking
9.8
CRITICAL
EPSS
1.2%
2024 CWE-648 1 PoC

The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

CVE-2025-1315
InWave Jobs Web Windows
9.8
CRITICAL
EPSS
0.1%
2025 CWE-288 1 PoC

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVE-2025-54123
hoverfly Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
58.1%
2025 CWE-20 0 PoCs

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command injection vulnerability at `/api/v2/hoverfly/middleware` endpoint due to insufficient validation and sanitization in user input. The vulnerability exists in the middleware management API endpoint `/api/v2/hoverfly/middleware`. This issue is born due to combination of three code level flaws: Insufficient Input Validation in middleware.go line 94-96; Unsafe Command Execution in local_middleware.go line 14-19; and Immediate Execution During Testing in hov