38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2013-10067
Glossword Web
9.4
CRITICAL
EPSS
32.1%
2013 CWE-434 3 PoCs

Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the gw_temp/a/ directory. Due to insufficient validation of file type and path, attackers can upload and execute PHP payloads, resulting in remote code execution.

CVE-2014-125118
eScan Web Management Console Web
9.4
CRITICAL
EPSS
47.2%
2014 CWE-78 3 PoCs

A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary commands via a specially crafted password value. Successful exploitation results in remote code execution. Privilege escalation to root is possible by abusing the runasroot utility with mwconf-level privileges.

CVE-2023-0017
NetWeaver AS for Java Web
9.4
CRITICAL
EPSS
5.0%
2023 CWE-284 1 PoC

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.

CVE-2020-6238
SAP Commerce Web
9.3
CRITICAL
EPSS
0.4%
2020 1 PoC

SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.

CVE-2023-2507
Cordova Plugin Web
9.3
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.

CVE-2024-2796
Akana API Platform Web
9.3
CRITICAL
EPSS
0.4%
2024 CWE-918 1 PoC

A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

CVE-2023-53975
Atom CMS Web Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVE-2024-56145
🔥 KEV cms Web ⚡ nuclei
9.3
CRITICAL
EPSS
94.1%
2024 CWE-94 3 PoCs

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.

CVE-2024-58307
CSZCMS Web Database
9.3
CRITICAL
EPSS
0.1%
2024 CWE-89 1 PoC

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

CVE-2024-58301
Purei CMS Web Database
9.3
CRITICAL
EPSS
0.0%
2024 CWE-89 1 PoC

Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through unfiltered user input parameters. Attackers can exploit vulnerable endpoints like getAllParks.php and events-ajax.php by injecting crafted SQL payloads to potentially extract or modify database information.

CVE-2020-37123
Pinger Web ⚡ nuclei
9.3
CRITICAL
EPSS
16.6%
2020 CWE-78 1 PoC

Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.

CVE-2023-1244
answerdev/answer Web
9.3
CRITICAL
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2020-5260
git Web
9.3
CRITICAL
EPSS
37.9%
2020 CWE-20 4 PoCs

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure storage provided by the operating system. Specially-crafted URLs that contain an encoded newline can inject unintended values into the credential helper protocol stream, causing the credential helper to retrieve the password for one server (e.g., good.example.com) for an HTTP request being made to another server (e.g., evil.example.com), resul

CVE-2020-37071
CraftCMS Web
9.3
CRITICAL
EPSS
0.6%
2020 CWE-502 1 PoC

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.

CVE-2019-25687
Pegasus CMS Web
9.3
CRITICAL
EPSS
1.1%
2019 CWE-22 1 PoC

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.

CVE-2020-36877
ReQuest Serious Play Pro Web
9.3
CRITICAL
EPSS
0.4%
2020 CWE-78 2 PoCs

ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on the server.

CVE-2021-47753
phpKF CMS Web
9.3
CRITICAL
EPSS
0.3%
2021 CWE-434 1 PoC

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.

CVE-2024-0012
🔥 KEV Cloud NGFW Web Networking Cloud ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-306 13 PoCs

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice d

CVE-2020-36875
AccessAlly Web Windows
9.3
CRITICAL
EPSS
0.1%
2020 CWE-94 1 PoC

AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web server process, resulting in remote code execution.

CVE-2020-37186
Chevereto Web
9.3
CRITICAL
EPSS
0.1%
2020 CWE-94 1 PoC

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.