94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47757
Chikitsa Patient Management System Web
8.7
HIGH
EPSS
0.6%
2021 CWE-434 1 PoC

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server.

CVE-2021-36800
Akaunting Web
8.7
HIGH
EPSS
0.3%
2021 CWE-94 1 PoC

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

CVE-2021-47802
Tenda D151 & D301 Networking
8.7
HIGH
EPSS
0.5%
2021 CWE-306 1 PoC

Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers to retrieve router configuration files. Attackers can send a request to /goform/getimage endpoint to download configuration data including admin credentials without authentication.

CVE-2009-10005
Web Appliance General
8.7
HIGH
EPSS
49.6%
2009 CWE-552 2 PoCs

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via a CGI endpoint, allowing unauthenticated attackers to retrieve arbitrary files from the filesystem. By crafting a POST request to /cgi-bin/ck/mimencode with traversal and output parameters, attackers can read sensitive files such as /etc/passwd outside the webroot.

CVE-2017-20220
Serviio PRO Web
8.7
HIGH
EPSS
0.2%
2017 CWE-306 3 PoCs

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.

CVE-2017-20222
SDT-CS3B1 Networking Cloud
8.7
HIGH
EPSS
0.1%
2017 CWE-306 2 PoCs

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of service by forcing the router to restart.

CVE-2017-20213
FLIR Thermal Camera F/FC/PT/D Stream General
8.7
HIGH
EPSS
0.2%
2017 CWE-306 3 PoCs

FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows remote attackers to access live camera streams without credentials. Attackers can exploit the vulnerability to view unauthorized thermal camera video feeds across multiple camera series without requiring any authentication.

CVE-2017-20212
FLIR Thermal Camera F/FC/PT/D Web
8.7
HIGH
EPSS
0.4%
2017 CWE-22 2 PoCs

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains an information disclosure vulnerability that allows unauthenticated attackers to read arbitrary files through unverified input parameters. Attackers can exploit the /var/www/data/controllers/api/xml.php readFile() function to access local system files without authentication.

CVE-2017-20215
FLIR Thermal Camera FC-S/PT General
8.7
HIGH
EPSS
0.5%
2017 CWE-78 3 PoCs

FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that allows attackers to execute shell commands with root privileges. Authenticated attackers can inject arbitrary shell commands through unvalidated input parameters to gain complete control of the thermal camera system.

CVE-2017-20217
Serviio PRO Web
8.7
HIGH
EPSS
0.1%
2017 CWE-306 3 PoCs

Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows unauthenticated attackers to access sensitive information. Remote attackers can send specially crafted requests to the REST API endpoints to retrieve potentially sensitive configuration data without authentication.

CVE-2012-10056
PHP Volunteer Management Web
8.7
HIGH
EPSS
36.8%
2012 CWE-434 3 PoCs

PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely. The application ships with default credentials, making exploitation trivial. Once authenticated, the attacker can upload a PHP shell and trigger it via a direct GET request.

CVE-2012-10048
Zenoss Core General
8.7
HIGH
EPSS
54.3%
2012 CWE-22 4 PoCs

Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() call in ZenossInfo.py without proper sanitation, allowing authenticated users to execute arbitrary commands on the server as the zenoss user.

CVE-2012-10034
ClanSphere General
8.7
HIGH
EPSS
23.2%
2012 CWE-22 2 PoCs

ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails to sanitize user-supplied input, allowing attackers to traverse directories and read arbitrary files outside the web root. The vulnerability is further exacerbated by null byte injection (%00) to bypass file extension checks.

CVE-2012-10032
Maxthon3 Browser Web
8.7
HIGH
EPSS
48.6%
2012 CWE-79 3 PoCs

Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) via the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw enables modification of browser configuration and execution of arbitrary code through Maxthon’s exposed DOM APIs, including maxthon.program.Program.launch() and maxthon.io.writeDataURL(). Exploitation requires user interaction, typically by visiting a malicious webpage that triggers the injection.

CVE-2012-10061
Music Host Server Web
8.7
HIGH
EPSS
55.6%
2012 CWE-22 3 PoCs

Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input. Attackers can traverse directories and access sensitive files outside the intended web root.

CVE-2012-10042
Sflog! CMS Web
8.7
HIGH
EPSS
47.6%
2012 CWE-434 3 PoCs

Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uploaded, the file can be executed remotely, resulting in full remote code execution.

CVE-2012-10062
XAMPP Web
8.7
HIGH
EPSS
61.8%
2012 CWE-434 2 PoCs

A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload and execute arbitrary PHP code. The WebDAV service, accessible via /webdav/, accepts HTTP PUT requests using default credentials. This permits attackers to upload a malicious PHP payload and trigger its execution via a subsequent GET request, resulting in remote code execution on the server.

CVE-2025-9642
GitLab DevOps
8.7
HIGH
EPSS
0.0%
2025 CWE-79 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

CVE-2025-9250
RE6250 General
8.7
HIGH
EPSS
0.3%
2025 CWE-121 1 PoC

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function setPWDbyBBS of the file /goform/setPWDbyBBS. Such manipulation of the argument hint leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-11408
DI-7001 MINI General
8.7
HIGH
EPSS
0.2%
2025 CWE-120 1 PoC

A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.