Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2025-52395 An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly | 9.8 | CRITICAL | — | 0 |
| CVE-2023-42276 hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-3651 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection.This issue affects E-Commerce Software: befor... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-57754 eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will all... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-34184 Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-52352 Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-47966 Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-36846 An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. Th... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-32242 Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-27214 A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. ... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-6436 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: throug... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-54952 An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effec... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41527 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-37089 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-37090 A server-side request forgery vulnerability exists in HPE StoreOnce Software. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-28255 OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-37095 A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-37096 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-53187 Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability ma... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-49217 An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerabili... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-46199 Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields | 9.8 | CRITICAL | — | 0 |
| CVE-2024-28423 Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via upload... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-52480 Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-7642 The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-8660 Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-28388 SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCo... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-6918 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-52483 Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-25153 A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-57157 Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-5306 Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778 | 9.8 | CRITICAL | — | 0 |
| CVE-2024-50640 jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function | 9.8 | CRITICAL | — | 0 |
| CVE-2024-57154 Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-57155 Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-5310 Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or mod... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-6895 The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. Th... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-25247 SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-34069 An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP p... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-41525 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-34070 A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible ... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-34071 A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgra... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-6943 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versio... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-24285 Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite. Aff... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-14495 webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-14529 OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-12288 An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a we... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-13478 The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-11356 The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCale... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-13573 A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker t... | 9.8 | CRITICAL | — | 0 |
| CVE-2017-18377 An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.