4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2012-10026
Wordpress Plugin Web Windows
10.0
CRITICAL
EPSS
69.7%
2012 CWE-434 3 PoCs

The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once uploaded, the attacker can execute the file via a direct HTTP GET request, resulting in remote code execution under the web server’s context.

CVE-2012-5862
eSolar Web
10.0
UNKNOWN
EPSS
18.3%
2012 CWE-259 1 PoC

These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

CVE-2012-10047
Cyclope Employee Surveillance Solution Web Database
10.0
CRITICAL
EPSS
53.2%
2012 CWE-89 4 PoCs

Cyclope Employee Surveillance Solution versions 6.x is vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to inject arbitrary SQL statements. This can be leveraged to write and execute a malicious PHP file on disk, resulting in remote code execution under the SYSTEM user context.

CVE-2012-10025
WordPress Plugin Web Windows
10.0
CRITICAL
EPSS
50.2%
2012 CWE-98 2 PoCs

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configuration directive allow_url_include is enabled (default: Off), an unauthenticated attacker can exploit the acf_abspath POST parameter to include and execute arbitrary remote PHP code. This leads to remote code execution under the web server’s context, allowing full compromise of the host.

CVE-2012-10044
MobileCartly Web
10.0
CRITICAL
EPSS
64.7%
2012 CWE-434 3 PoCs

MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authentication or authorization checks before invoking file_put_contents() on attacker-controlled input. An unauthenticated attacker can exploit this flaw by sending crafted HTTP GET requests to savepage.php, specifying both the filename and content. This allows arbitrary file creation within the pages/ directory or any writable path on the server, allowing remote code execution.

CVE-2012-6437
1756-ENBT, 1756-EWEB, 1768-ENBT, 1768-EWEB communication modules General
10.0
UNKNOWN
EPSS
11.8%
2012 CWE-287 1 PoC

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter;

CVE-2012-5863
eSolar General
10.0
UNKNOWN
EPSS
9.1%
2012 CWE-78 1 PoC

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.

CVE-2012-10035
TurboFTP Server General
10.0
CRITICAL
EPSS
53.3%
2012 CWE-120 2 PoCs

Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges.

CVE-2012-6069
CODESYS Control Runtime embedded General
10.0
CRITICAL
EPSS
2.2%
2012 CWE-23 1 PoC

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.

CVE-2012-10058
R4 Embedded Server Web
10.0
CRITICAL
EPSS
58.6%
2012 CWE-121 3 PoCs

RabidHamster R4 v1.25 contains a stack-based buffer overflow vulnerability due to unsafe use of sprintf() when logging malformed HTTP requests. A remote attacker can exploit this flaw by sending a specially crafted URI, resulting in arbitrary code execution under the context of the web server process.

CVE-2025-53833
larecipe Web ⚡ nuclei
10.0
CRITICAL
EPSS
16.8%
2025 CWE-1336 1 PoC

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration. Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.

CVE-2025-20337
🔥 KEV Cisco Identity Services Engine Software Web Networking
10.0
CRITICAL
EPSS
1.0%
2025 CWE-74 1 PoC

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVE-2025-10035
🔥 KEV GoAnywhere MFT General ⚡ nuclei
10.0
CRITICAL
EPSS
55.2%
2025 CWE-77 4 PoCs

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CVE-2025-47419
Automate VX Web
10.0
CRITICAL
EPSS
0.2%
2025 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

CVE-2025-50567
Software Genérico Web Database
10.0
CRITICAL
EPSS
0.3%
2025 1 PoC

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-controlled SQL statements, potentially leading to arbitrary PHP code execution.

CVE-2025-13390
WP Directory Kit Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
35.0%
2025 CWE-303 2 PoCs

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

CVE-2025-24201
🔥 KEV Safari General
10.0
CRITICAL
EPSS
0.2%
2025 5 PoCs

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on version

CVE-2025-59528
Flowise Web ⚡ nuclei
10.0
CRITICAL
EPSS
83.9%
2025 CWE-94 0 PoCs

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes t

CVE-2025-34077
WordPress Pie Register Plugin Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
76.2%
2025 CWE-434 4 PoCs

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.

CVE-2025-55241
Microsoft Entra Cloud
10.0
CRITICAL
EPSS
0.2%
2025 CWE-287 2 PoCs

Azure Entra ID Elevation of Privilege Vulnerability