38275 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-47066
lobe-chat Web
9.0
CRITICAL
EPSS
5.8%
2024 CWE-918 1 PoC

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.

CVE-2021-43047
TIBCO PartnerExpress Web
9.0
CRITICAL
EPSS
0.3%
2021 1 PoC

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: versions 6.2.1 and below.

CVE-2020-4427
🔥 KEV Data Risk Manager Web ⚡ nuclei
9.0
CRITICAL
EPSS
92.7%
2020 2 PoCs

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVE-2025-54309
🔥 KEV CrushFTP Web
9.0
CRITICAL
EPSS
77.8%
2025 CWE-420 10 PoCs

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

CVE-2025-8264
z-push/z-push-dev Web Database Windows
9.0
CRITICAL
EPSS
0.1%
2025 CWE-89 1 PoC

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php defi

CVE-2025-22144
Nameless Web
9.0
CRITICAL
EPSS
0.4%
2025 CWE-610 1 PoC

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromi

CVE-2023-5843
Ads by datafeedr.com Web Windows
9.0
CRITICAL
EPSS
9.3%
2023 CWE-94 1 PoC

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are limited, they cannot be specified arbitrarily.

CVE-2023-4202
EKI-1524 Web
9.0
CRITICAL
EPSS
0.2%
2023 CWE-79 3 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

CVE-2024-35305
Pandora FMS Web Database
8.9
HIGH
EPSS
0.4%
2024 CWE-89 1 PoC

Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

CVE-2023-5351
salesagility/suitecrm Web
8.9
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2024-24550
Bludit Web
8.9
HIGH
EPSS
0.1%
2024 CWE-77 1 PoC

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVE-2023-42819
jumpserver Web Networking
8.9
HIGH
EPSS
38.1%
2023 CWE-22 2 PoCs

JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system. A user can use the 'Job-Template' menu and create a playbook named 'test'. Get the playbook id from the detail page, like 'e0adabef-c38f-492d-bd92-832bacc3df5f'. An attacker can exploit the directory traversal flaw using the provided URL to access and retrieve the contents of the file. `https://jumpserver-ip/api/v1/ops/playbook/e0adabef-c38f-492d-bd92-832bacc3df5f/file/?key=../../../../../../../etc/passwd` a similar method to modify the file content is also present. This iss

CVE-2023-27524
🔥 KEV Apache Superset Web ⚡ nuclei
8.9
HIGH
EPSS
84.0%
2023 CWE-1188 18 PoCs

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `supe

CVE-2023-1758
thorsten/phpmyfaq Web
8.9
HIGH
EPSS
0.3%
2023 CWE-75 1 PoC

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2025-60507
Software Genérico Web
8.9
HIGH
EPSS
0.0%
2025 1 PoC

Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.

CVE-2026-38949
Software Genérico Web
8.9
HIGH
EPSS
0.0%
2026 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code

CVE-2024-49368
nginx-ui Web
8.9
HIGH
EPSS
57.7%
2024 CWE-20 1 PoC

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.

CVE-2024-24551
Bludit Web
8.9
HIGH
EPSS
0.2%
2024 CWE-77 1 PoC

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVE-2026-8208
gibbon Web
8.9
HIGH
EPSS
0.0%
2026 CWE-98 1 PoC

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.

CVE-2022-44724
Software Genérico Web
8.9
HIGH
EPSS
0.4%
2022 2 PoCs

The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.