33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36963
Intelbras Router RF 301K Web Networking
8.7
HIGH
EPSS
0.3%
2020 CWE-306 1 PoC

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

CVE-2020-37069
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-36925
Arteco Web Client DVR/NVR General
8.7
HIGH
EPSS
0.6%
2020 CWE-331 2 PoCs

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

CVE-2020-36895
i-Media Server Digital Signage Web
8.7
HIGH
EPSS
0.3%
2020 CWE-639 2 PoCs

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.

CVE-2020-36948
VestaCP General
8.7
HIGH
EPSS
0.3%
2020 CWE-863 2 PoCs

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

CVE-2020-37104
ASTPP General
8.7
HIGH
EPSS
0.1%
2020 CWE-538 1 PoC

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

CVE-2016-15056
Ubee EVW3226 Networking
8.7
HIGH
EPSS
0.5%
2016 CWE-538 3 PoCs

Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the web root after they are generated for download. These backup files remain accessible without authentication until the next reboot. A remote attacker on the local network can request 'Configuration_file.cfg' directly to obtain the backup archive. Because backup files are not encrypted, they expose sensitive information including the plaintext admin password, allowing full compromise of the device.

CVE-2016-20025
ZKTeco ZKAccess Professional General
8.7
HIGH
EPSS
0.0%
2016 CWE-552 2 PoCs

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malicious code for privilege escalation.

CVE-2016-20034
Wowza Streaming Engine General
8.7
HIGH
EPSS
0.0%
2016 CWE-352 2 PoCs

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.

CVE-2016-15055
IP-Camera (VN-T216VPRU) General
8.7
HIGH
EPSS
1.5%
2016 CWE-22 1 PoC

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

CVE-2016-15047
IP Camera, NVR, and DVR Devices Cloud
8.7
HIGH
EPSS
0.4%
2016 CWE-78 3 PoCs

AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can supply crafted input to execute arbitrary system commands as root. Successful exploitation grants full control of the device, and - depending on deployment and whether the device stores credentials or has network reachability to internal systems - may enable credential theft, later

CVE-2018-25139
FLIR AX8 Thermal Camera General
8.7
HIGH
EPSS
0.2%
2018 CWE-306 2 PoCs

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.

CVE-2018-25246
Wikipedia General
8.7
HIGH
EPSS
0.0%
2018 CWE-306 1 PoC

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.

CVE-2018-25144
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Arbitrary File Attacks General
8.7
HIGH
EPSS
0.3%
2018 CWE-22 2 PoCs

Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system modifications through GET and POST requests.

CVE-2018-25245
7 Tik General
8.7
HIGH
EPSS
0.1%
2018 CWE-601 1 PoC

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

CVE-2018-25308
Buddypress Xprofile Custom Fields Type General
8.7
HIGH
EPSS
0.3%
2018 CWE-22 1 PoC

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink files from the server.

CVE-2018-25143
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Backdoor Jailbreak Networking
8.7
HIGH
EPSS
0.2%
2018 CWE-78 2 PoCs

Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.

CVE-2018-25294
CEWE Photoshow General
8.7
HIGH
EPSS
0.1%
2018 CWE-120 1 PoC

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

CVE-2018-25158
Chamillo LMS Web
8.7
HIGH
EPSS
0.1%
2018 CWE-434 1 PoC

Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files.

CVE-2018-25113
PACS Web Server General
8.7
HIGH
EPSS
42.8%
2018 CWE-22 2 PoCs

An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remote attackers to read arbitrary files on the underlying system by sending a crafted request to the /exportFile endpoint using the UID parameter. Successful exploitation can reveal sensitive files accessible by the web server user.