Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2024-38346 The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these c... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-27100 Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force prot... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-27060 LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-28667 The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-28662 The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_s... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-27638 An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET paramet... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-27637 An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to explo... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-0740 Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is inclu... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-27224 An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-25589 A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows ... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-51478 Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-32041 FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-0929 SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete all database information by injecting a malicious SQL statement via the βabsβ par... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-28668 Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46723 This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-12248 Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could resul... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-0680 Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-48283 A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functio... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-48259 There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-48255 There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code executio... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-48710 iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in th... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-25234 Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-25233 Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-25231 Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-48284 A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functio... | 9.8 | CRITICAL | β | 0 |
| CVE-2012-1710 Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via un... | 9.8 | CRITICAL | KEV | 0 |
| CVE-2025-24905 WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_codigobarras_cobranca.php` endpoint. This vulnerability could allow an a... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-27099 The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submo... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-24906 WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_cobranca.php` endpoint. This vulnerability could allow an autho... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-26550 A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-24957 WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_socio.php` endpoint. This vulnerability could allow an authoriz... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24189 An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-35370 An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-25691 Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-25802 SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-33898 Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote c... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24205 Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml). | 9.8 | CRITICAL | β | 0 |
| CVE-2025-1044 Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. A... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36231 pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-25530 Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who ... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24104 Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-45599 Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regard... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24107 hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attac... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-47926 Tecnick TCExam β CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24080 A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24320 An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46637 Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-24184 TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-45677 SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-45564 SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.