38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-9874
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
87.6%
2019 0 PoCs

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

CVE-2020-15434
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When parsing the canal parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9745.

CVE-2020-10826
Software Genérico Web
9.8
CRITICAL
EPSS
30.0%
2020 2 PoCs

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

CVE-2025-57118
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2025 1 PoC

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

CVE-2023-41506
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2013-2251
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2013 7 PoCs

Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.

CVE-2019-25213
Advanced Access Manager – Access Governance for WordPress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
40.2%
2019 CWE-22 0 PoCs

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

CVE-2019-1663
RV110W Wireless-N VPN Firewall Web Networking
9.8
CRITICAL
EPSS
87.2%
2019 CWE-119 9 PoCs

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating syst

CVE-2024-9822
Pedalo Connector Web Windows
9.8
CRITICAL
EPSS
14.6%
2024 CWE-288 1 PoC

The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it does not exist, then to the first administrator.

CVE-2023-31903
Software Genérico Web
9.8
CRITICAL
EPSS
6.1%
2023 1 PoC

GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.

CVE-2024-11068
DSL6740C Web Networking
9.8
CRITICAL
EPSS
1.2%
2024 CWE-648 1 PoC

The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

CVE-2023-30185
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2023 2 PoCs

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

CVE-2020-3250
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
89.7%
2020 CWE-20 2 PoCs

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2025-61246
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.0%
2025 1 PoC

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

CVE-2024-0705
Payment Gateway of Stripe for WooCommerce Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
19.7%
2024 CWE-89 0 PoCs

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-31666
Software Genérico Web
9.8
CRITICAL
EPSS
27.1%
2024 1 PoC

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

CVE-2024-48956
Software Genérico Web
9.8
CRITICAL
EPSS
11.6%
2024 CWE-1394 1 PoC

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution.

CVE-2025-7401
Premium Age Verification / Restriction for WordPress Web Windows
9.8
CRITICAL
EPSS
1.9%
2025 CWE-798 1 PoC

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVE-2024-57450
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

CVE-2014-6287
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2014 17 PoCs

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.