878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-28734
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
11.3%
2024 1 PoC

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

CVE-2024-11044
automatic1111/stable-diffusion-webui General ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-10812
binary-husky/gpt_academic General ⚡ nuclei
6.1
MEDIUM
EPSS
0.7%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2020-11034
GLPI General ⚡ nuclei
6.1
MEDIUM
EPSS
58.7%
2020 CWE-601 0 PoCs

In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.

CVE-2023-44012
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
15.2%
2023 0 PoCs

Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.

CVE-2023-22432
web2py General ⚡ nuclei
6.1
MEDIUM
EPSS
40.8%
2023 1 PoC

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

CVE-2025-32970
xwiki-platform General ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2025 CWE-601 0 PoCs

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki instance that redirects to any URL. This issue has been patched in versions 15.10.13, 16.4.4, and 16.8.0.

CVE-2023-33405
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
51.4%
2023 1 PoC

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

CVE-2024-10908
lm-sys/fastchat General ⚡ nuclei
6.1
MEDIUM
EPSS
1.0%
2024 CWE-601 0 PoCs

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

CVE-2023-49293
vite General ⚡ nuclei
6.1
MEDIUM
EPSS
7.8%
2023 CWE-79 0 PoCs

Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`<script type="module">...</script>`), it is possible to inject arbitrary HTML into the transformed output by supplying a malicious URL query string to `server.transformIndexHtml`. Only apps using `appType: 'custom'` and using the default Vite HTML middleware are affected. The HTML entry must also contain an inline script. The attack requires a user to click o

CVE-2022-28923
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
2.9%
2022 0 PoCs

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVE-2021-21345
xstream General ⚡ nuclei
5.8
MEDIUM
EPSS
88.1%
2021 CWE-94 5 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2022-45835
PhonePe Payment Solutions General ⚡ nuclei
5.8
MEDIUM
EPSS
71.1%
2022 CWE-918 0 PoCs

Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

CVE-2025-1035
KLog Server General ⚡ nuclei
5.7
MEDIUM
EPSS
67.7%
2025 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

CVE-2024-55415
Software Genérico General ⚡ nuclei
5.7
MEDIUM
EPSS
59.7%
2024 0 PoCs

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

CVE-2023-29506
xwiki-platform General ⚡ nuclei
5.4
MEDIUM
EPSS
11.5%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

CVE-2024-30464
Social Icons Widget & Block by WPZOOM General ⚡ nuclei
5.4
MEDIUM
EPSS
43.5%
2024 CWE-862 0 PoCs

Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15.

CVE-2024-8021
gradio-app/gradio General ⚡ nuclei
5.4
MEDIUM
EPSS
2.4%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

CVE-2023-27292
OpenCATS General ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2023 1 PoC

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.