33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3224
ionicabizau/parse-url General
9.4
CRITICAL
EPSS
0.3%
2022 CWE-115 1 PoC

Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.

CVE-2022-1682
neorazorx/facturascripts Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser

CVE-2022-1592
clinical-genomics/scout Web
9.4
CRITICAL
EPSS
0.2%
2022 CWE-918 2 PoCs

Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

CVE-2022-1782
erudika/para Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11.

CVE-2022-46164
NodeBB General
9.4
CRITICAL
EPSS
56.8%
2022 CWE-665 1 PoC

NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1. Users are advised to upgrade. Users unable to upgrade may cherry-pick commit `48d143921753914da45926cca6370a92ed0c46b8` into their codebase to patch the exploit.

CVE-2022-0942
star7th/showdoc Web
9.4
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2024-46636
Software Genérico Database
9.4
CRITICAL
EPSS
0.0%
2024 1 PoC

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter

CVE-2014-125113
KACE K1000 Systems Management Appliance Web
9.3
CRITICAL
EPSS
56.5%
2014 CWE-434 3 PoCs

An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.

CVE-2014-0781
CENTUM CS 3000 General
9.3
UNKNOWN
EPSS
7.5%
2014 CWE-122 2 PoCs

Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.

CVE-2014-125116
HybridAuth Web
9.3
CRITICAL
EPSS
54.5%
2014 CWE-434 4 PoCs

A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. The script remains accessible after deployment and fails to sanitize input before writing to the application’s config.php file. An unauthenticated attacker can inject arbitrary PHP code into config.php, which is later executed when the file is loaded. This allows attackers to achieve remote code execution on the server. Exploitation of this issue will overwrite the existing configuration, rendering the application non-functional.

CVE-2014-125117
DSP-W215 Web
9.3
CRITICAL
EPSS
48.5%
2014 CWE-121 4 PoCs

A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to achieve remote code execution with system-level privileges.

CVE-2013-10064
ActFax Server Networking
9.3
CRITICAL
EPSS
63.8%
2013 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in ActFax Server version 5.01. The server's RAW protocol interface fails to safely process user-supplied data in @F506 fax header fields due to insecure usage of strcpy. Remote attackers can exploit this vulnerability by sending specially crafted @F506 fields, potentially leading to arbitrary code execution. Successful exploitation requires network access to TCP port 4559 and does not require authentication.

CVE-2013-10054
LibrettoCMS Web
9.3
CRITICAL
EPSS
73.7%
2013 CWE-434 3 PoCs

An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager plugin. The upload handler located at adm/ui/js/ckeditor/plugins/pgrfilemanager/php/upload.php fails to properly validate file extensions, allowing attackers to upload files with misleading extensions and subsequently rename them to executable .php scripts. This enables remote code execution on the server without authentication.

CVE-2013-10055
Havalite CMS Web
9.3
CRITICAL
EPSS
73.5%
2013 CWE-434 2 PoCs

An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a crafted multipart/form-data POST request. Once uploaded, the attacker can access the file directly under havalite/tmp/files/, resulting in remote code execution.

CVE-2013-10034
KServer General
9.3
CRITICAL
EPSS
40.5%
2013 CWE-434 2 PoCs

An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an attacker can upload a file with an .asp extension to a web-accessible directory, which can then be invoked to execute arbitrary code with the privileges of the IUSR account. The vulnerability enables remote code execution without prior authentication and was resolved in version 6.3

CVE-2013-10033
Kimai Web Database
9.3
CRITICAL
EPSS
47.2%
2013 CWE-89 4 PoCs

An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental conditions. This can lead to remote code execution by writing a PHP payload to the web-accessible temporary directory. The vulnerability has been confirmed in versions including 0.9.2.beta, 0.9.2.1294.beta, and 0.9.2.1306-3.

CVE-2013-10051
InstantCMS Web
9.3
CRITICAL
EPSS
75.8%
2013 CWE-95 3 PoCs

A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit this flaw by sending a crafted HTTP GET request with a base64-encoded payload in the Cmd header, resulting in arbitrary PHP code execution within the context of the web server.

CVE-2013-10042
freeFTPd General
9.3
CRITICAL
EPSS
60.2%
2013 CWE-121 3 PoCs

A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PASS command. When an attacker sends a specially crafted password string, the application fails to validate input length, resulting in memory corruption. This can lead to denial of service or arbitrary code execution. Exploitation requires the anonymous user account to be enabled.

CVE-2013-10037
WebTester Web
9.3
CRITICAL
EPSS
67.2%
2013 CWE-78 2 PoCs

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

CVE-2013-10038
FlashChat Web
9.3
CRITICAL
EPSS
64.0%
2013 CWE-434 3 PoCs

An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in arbitrary code execution as the web server user.