Vulnerabilities
38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-5789 | Vulnerability related to an unquoted search path in CivetWeb v1.16. Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration. NVD description · AI analysis pending | 8.5 | <1% |
| — | ||
| CVE-2025-13250 +1 in the same advisory: …13251 | A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper access controls. The attack may be initiated remotely. The exploit is now public and may be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-55763 | Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2025-27590 | Unauthenticated Path Traversal in Oxidized Web RANCID Migration Page CVE-2025-27590 is a path traversal flaw (CWE-22) in the RANCID migration page of oxidized-web, the web interface for the Oxidized network device configuration backup tool, affecting all versions before 0.15.0. An unauthenticated attacker can send a crafted HTTP request to the migration page with attacker-controlled path input, allowing them to manipulate files on the host as the service. As a result, the attacker gains control over the Linux user account under which oxidized-web runs, which typically means the ability to read, write, or execute as that account on the Oxidized server — a system that stores network device credentials and configurations. Any deployment running oxidized-web prior to 0.15.0 is affected, including installations where the web interface is exposed to untrusted networks. Exploitation has not been observed in the wild and no public proof-of-concept is known, but the 27.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days. Do: Upgrade oxidized-web to version 0.15.0 or later. Until then, restrict access to the oxidized-web interface to trusted management networks via firewall rules, ACLs, or an authenticating reverse proxy, since the vulnerable page requires no authentication. Also audit the Linux account running oxidized-web (e.g., check authorized_keys, cron jobs, and recent activity) for signs of compromise. | 9.8 | 28% |
| nichelikely low thousands of deployments worldwide, mostly on internal management networks; internet-exposed instances probably in the hundreds | ||
| CVE-2024-12358 | A vulnerability was found in WeiYe-Jing datax-web 2.1.1. A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.3 | 5% | PoC |
| — | |
| CVE-2022-4960 | A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component Nickname Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250238 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-7116 | A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality of the file /api/log/killJob of the component HTTP POST Request Handler. The manipulation of the argument processId leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249086 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | 10% | PoC |
| — | |
| CVE-2023-25015 | Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF. Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2023-0287 | A vulnerability was found in ityouknow favorites-web. A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218294 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-46478 | The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via cra The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-4236 | Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2019-25088 | A vulnerability was found in ytti Oxidized Web. A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2020-24600 | Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request. Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2022-31542 | The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — | |
| CVE-2022-31534 | The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — | |
| CVE-2022-31504 | The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used uns The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% | PoC ×2 |
| — | |
| CVE-2021-43725 | There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web scri There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter. NVD description · AI analysis pending | 6.1 | 3% | PoC |
| — | |
| CVE-2021-33966 | Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page. Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-27304 | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mech The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2021-41568 | Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and u Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2021-40973 | Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web scrip Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter. NVD description · AI analysis pending | 6.1 | 2% | PoC |
| — | |
| CVE-2021-23404 | This affects all versions of package sqlite-web. This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2021-3286 | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-35545 | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. Time-based SQL injection exists in Spotweb 1.4.9 via the query string. NVD description · AI analysis pending | 9.8 | 4% |
| — | ||
| CVE-2019-10185 | It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. NVD description · AI analysis pending | 8.6 group max | 4% |
| — | ||
| CVE-2018-16450 | CraftedWeb through 2013-09-24 has reflected XSS via the p parameter. CraftedWeb through 2013-09-24 has reflected XSS via the p parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-12919 | In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-12684 | Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file. NVD description · AI analysis pending | 7.1 | 1% |
| — | ||
| CVE-2017-12097 | An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2017-6087 | EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php. NVD description · AI analysis pending | 8.8 | 7% | PoC |
| — |