Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2025-53006 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryar... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-47029 An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component | 9.8 | CRITICAL | β | 0 |
| CVE-2025-49851 ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-57190 Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-25565 SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-25568 SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN so... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-1744 Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-55160 GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-22952 elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-11284 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's ide... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-11285 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's ide... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-11286 The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior to authen... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42556 Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42558 Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-6330 The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-10901 In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attacker... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-6459 The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the template parameter. This makes it possible for unauthenticated attacker to include ... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42850 An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-56180 CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raftΒ pluginΒ module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to ... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-53529 WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properl... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-53527 WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue all... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-34399 Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-37226 Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-37227 Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-37231 Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-37099 A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-45065 employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-43933 fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-46256 A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42639 H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-55215 An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-43932 JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-57430 An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw c... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-43931 flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42637 H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-20082 In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed f... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-26770 TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-52101 linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-57052 An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-0357 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and ... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-40912 CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be... | 9.8 | CRITICAL | β | 0 |
| CVE-2025-6934 The Opal Estate Pro β Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42815 In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field in /usr/bin/httpd. Attackers who successfully exploit this vuln... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-4976 Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, CVE-2014-8140 a... | 9.8 | CRITICAL | β | 0 |
| CVE-2024-36536 Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | 9.8 | CRITICAL | β | 0 |
| CVE-2025-43930 Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-36540 Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-36539 Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-48112 A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42835 langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.