38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2018-25270
ThinkPHP Web
9.3
CRITICAL
EPSS
0.9%
2018 CWE-639 1 PoC

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

CVE-2010-20059
FreeNAS Web
9.3
CRITICAL
EPSS
48.6%
2010 CWE-78 2 PoCs

FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

CVE-2010-20113
EasyFTP Server Web
9.3
CRITICAL
EPSS
62.7%
2010 CWE-121 2 PoCs

EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially corrupting control flow structures. The vulnerability is exposed through the embedded web server and does not require authentication due to default anonymous access. The issue was resolved in version 1.7.0.12, after which the product was renamed to UplusFtp.

CVE-2010-20112
Amlibweb Library Management System Web Windows
9.3
CRITICAL
EPSS
52.3%
2010 CWE-121 2 PoCs

Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured Exception Handler (SEH). Additionally, malformed parameter names followed by an equals sign may result in unintended control flow behavior. This vulnerability is exposed through IIS and affects legacy Windows deployments

CVE-2010-10013
AjaXplorer Web Networking
9.3
CRITICAL
EPSS
64.3%
2010 CWE-78 2 PoCs

An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell metacharacters, remote attackers can execute arbitrary system commands on the server with the privileges of the web server process.

CVE-2011-10033
is-human WordPress Plugin Web Windows
9.3
CRITICAL
EPSS
0.1%
2011 CWE-95 1 PoC

The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of attacker-supplied PHP and OS commands. This may result in arbitrary code execution as the webserver user, site compromise, or data exfiltration. The is-human plugin was made defunct in June 2008 and is no longer available for download. This vulnerability was exploited in the wild in March 2012.

CVE-2011-10026
Spreecommerce Web
9.3
CRITICAL
EPSS
68.6%
2011 CWE-78 2 PoCs

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

CVE-2022-33965
WP Visitor Statistics (WordPress plugin) Web Database Windows ⚡ nuclei
9.3
CRITICAL
EPSS
42.7%
2022 CWE-89 0 PoCs

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

CVE-2022-21796
Software Genérico Web
9.3
CRITICAL
EPSS
0.7%
2022 CWE-20 1 PoC

A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-50794
Impact/Pulse/First Web
9.3
CRITICAL
EPSS
1.7%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

CVE-2022-1231
plantuml/plantuml Web
9.3
CRITICAL
EPSS
0.2%
2022 CWE-79 2 PoCs

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).

CVE-2022-47615
LearnPress – WordPress LMS Plugin Web Windows ⚡ nuclei
9.3
CRITICAL
EPSS
83.0%
2022 1 PoC

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CVE-2022-50912
ImpressCMS Web
9.3
CRITICAL
EPSS
0.2%
2022 CWE-434 1 PoC

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

CVE-2022-50893
VIAVIWEB Wallpaper Admin Web
9.3
CRITICAL
EPSS
1.1%
2022 CWE-434 1 PoC

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

CVE-2021-47932
TheCartPress Web Windows
9.3
CRITICAL
EPSS
0.1%
2021 CWE-862 1 PoC

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication.

CVE-2021-47933
MStore API Web Windows
9.3
CRITICAL
EPSS
0.2%
2021 CWE-306 1 PoC

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server.

CVE-2014-125126
Simple E-Document Web
9.2
CRITICAL
EPSS
65.6%
2014 CWE-434 3 PoCs

An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict file types and does not validate or sanitize user-supplied input, allowing attackers to upload malicious .php scripts. Authentication can be bypassed entirely by supplying a specially crafted cookie (access=3), granting access to the upload functionality without valid credentials. If file uploads are enabled on the server,

CVE-2026-41176
rclone Web Cloud ⚡ nuclei
9.2
CRITICAL
EPSS
6.3%
2026 CWE-306 0 PoCs

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive a

CVE-2026-27760
OpenCATS Web
9.2
CRITICAL
EPSS
0.1%
2026 CWE-94 2 PoCs

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.

CVE-2026-27175
MajorDoMo Web
9.2
CRITICAL
EPSS
26.0%
2026 CWE-78 1 PoC

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double quotes without sanitization via escapeshellarg(). The command is inserted into a database queue by safe_exec(), which performs no sanitization. The cycle_execs.php script, which is web-accessible without authentication, retrieves queued commands and passes them directly to exec(). An attacker can exploit a race condition by first triggering cycle_execs.php (which purges the queue and enters a pollin