878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks General ⚡ nuclei
7.5
HIGH
EPSS
31.5%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

CVE-2023-38205
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.2%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CVE-2024-2928
mlflow/mlflow General ⚡ nuclei
7.5
HIGH
EPSS
91.6%
2024 CWE-29 1 PoC

A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fixed in version 2.11.3. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../'. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system, including sensitive files like '/etc/passwd'. The vulnerability is a bypass to a previous patch that only addressed similar manipulation within the URI's query string, highlighting the nee

CVE-2024-6781
Calibre General ⚡ nuclei
7.5
HIGH
EPSS
93.7%
2024 CWE-22 1 PoC

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

CVE-2024-20767
🔥 KEV ColdFusion General ⚡ nuclei
7.4
HIGH
EPSS
94.0%
2024 CWE-284 6 PoCs

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

CVE-2022-0432
mastodon/mastodon General ⚡ nuclei
7.4
HIGH
EPSS
57.1%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

CVE-2020-28429
geojson2kml General ⚡ nuclei
7.3
HIGH
EPSS
84.8%
2020 1 PoC

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

CVE-2023-3643
Boss Mini General ⚡ nuclei
7.3
HIGH
EPSS
40.7%
2023 CWE-73 1 PoC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2025-56132
Software Genérico General ⚡ nuclei
7.3
HIGH
EPSS
2.6%
2025 1 PoC

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based lockout mechanisms to mitigate brute-force attacks, user enumeration remains possible by default. In versions prior to 4.2, no such user-level protection is in place, only basic IP-based rate limiting is enforced. This IP-based protection can be bypassed by distributing requests across

CVE-2025-36604
Unity General ⚡ nuclei
7.3
HIGH
EPSS
17.4%
2025 CWE-78 1 PoC

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.

CVE-2024-46507
Software Genérico General ⚡ nuclei
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

CVE-2024-27199
🔥 KEV TeamCity General ⚡ nuclei
7.3
HIGH
EPSS
91.4%
2024 CWE-23 1 PoC

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVE-2023-29084
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
93.9%
2023 2 PoCs

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

CVE-2024-0200
Enterprise Server General ⚡ nuclei
7.2
HIGH
EPSS
70.8%
2024 CWE-470 1 PoC

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-21683
Confluence Data Center General ⚡ nuclei
7.2
HIGH
EPSS
94.1%
2024 9 PoCs

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the

CVE-2024-38288
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
68.5%
2024 0 PoCs

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

CVE-2025-32813
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
11.2%
2025 0 PoCs

An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.

CVE-2024-54330
Hurrakify General ⚡ nuclei
7.2
HIGH
EPSS
72.5%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in hurraki Hurrakify hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from n/a through <= 2.4.

CVE-2024-54385
Radio Player General ⚡ nuclei
7.2
HIGH
EPSS
81.0%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

CVE-2023-33629
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
88.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.