878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-34023
Karel IP Phone IP1211 General ⚡ nuclei
8.5
HIGH
EPSS
2.8%
2025 CWE-22 1 PoC

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.

CVE-2023-1362
unilogies/bumsys General ⚡ nuclei
8.4
HIGH
EPSS
53.5%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

CVE-2023-3188
owncast/owncast General ⚡ nuclei
8.3
HIGH
EPSS
48.7%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

CVE-2024-22024
ICS General ⚡ nuclei
8.3
HIGH
EPSS
94.2%
2024 2 PoCs

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CVE-2023-6549
🔥 KEV NetScaler ADC General ⚡ nuclei
8.2
HIGH
EPSS
76.5%
2023 CWE-119 0 PoCs

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVE-2023-27351
🔥 KEV NG General ⚡ nuclei
8.2
HIGH
EPSS
87.0%
2023 CWE-287 0 PoCs

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

CVE-2023-46805
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.4%
2023 8 PoCs

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVE-2024-21893
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.3%
2024 2 PoCs

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

CVE-2024-38653
Avalanche General ⚡ nuclei
8.2
HIGH
EPSS
90.7%
2024 0 PoCs

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

CVE-2025-44177
Software Genérico General ⚡ nuclei
8.2
HIGH
EPSS
9.3%
2025 0 PoCs

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenticated attacker can remotely read arbitrary files on the underlying OS using encoded traversal sequences.

CVE-2025-32966
dataease General ⚡ nuclei
8.2
HIGH
EPSS
11.2%
2025 CWE-290 0 PoCs

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.

CVE-2025-49002
dataease General ⚡ nuclei
8.2
HIGH
EPSS
22.3%
2025 CWE-290 0 PoCs

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

CVE-2020-4463
Maximo Asset Management General ⚡ nuclei
8.2
HIGH
EPSS
85.8%
2020 1 PoC

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-0947
flatpressblog/flatpress General ⚡ nuclei
8.1
HIGH
EPSS
53.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2024-43425
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
89.3%
2024 3 PoCs

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

CVE-2021-41192
redash General ⚡ nuclei
8.1
HIGH
EPSS
79.6%
2021 CWE-1188 0 PoCs

Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. This issue only affects installations where the `REDASH_COOKIE_SECRET or REDASH_SECRET_KEY` environment variables have not been explicitly set. This issue does not affect users of the official Reda

CVE-2021-21479
SCIMono General ⚡ nuclei
8.1
HIGH
EPSS
78.2%
2021 0 PoCs

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

CVE-2025-57808
esphome General ⚡ nuclei
8.1
HIGH
EPSS
4.7%
2025 CWE-303 0 PoCs

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.