878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-2710
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation of the argument flag leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-43919
YARPP General ⚡ nuclei
5.3
MEDIUM
EPSS
84.5%
2024 CWE-862 1 PoC

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

CVE-2024-2863
LG LED Assistant General ⚡ nuclei
5.3
MEDIUM
EPSS
56.8%
2024 CWE-35 0 PoCs

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

CVE-2025-24582
12 Step Meeting List General ⚡ nuclei
5.3
MEDIUM
EPSS
6.4%
2025 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5.

CVE-2024-44762
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
14.9%
2024 0 PoCs

A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.

CVE-2021-28164
Eclipse Jetty General ⚡ nuclei
5.3
MEDIUM
EPSS
93.5%
2021 CWE-200 5 PoCs

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVE-2025-2709
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-33575
User Meta General ⚡ nuclei
5.3
MEDIUM
EPSS
4.7%
2024 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0.

CVE-2021-26086
🔥 KEV Jira Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.2%
2021 3 PoCs

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

CVE-2021-34429
Eclipse Jetty General ⚡ nuclei
5.3
MEDIUM
EPSS
93.8%
2021 CWE-200 4 PoCs

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.

CVE-2024-30570
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
13.2%
2024 1 PoC

An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2023-44982
Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina) General ⚡ nuclei
5.3
MEDIUM
EPSS
12.9%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.

CVE-2021-26085
🔥 KEV Confluence Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.0%
2021 3 PoCs

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2025-27218
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
76.1%
2025 0 PoCs

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

CVE-2023-41763
🔥 KEV Skype for Business Server 2015 CU13 General ⚡ nuclei
5.3
MEDIUM
EPSS
16.5%
2023 CWE-918 0 PoCs

Skype for Business Elevation of Privilege Vulnerability

CVE-2024-43283
Contest Gallery General ⚡ nuclei
5.3
MEDIUM
EPSS
15.6%
2024 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

CVE-2021-28169
Eclipse Jetty General ⚡ nuclei
5.3
MEDIUM
EPSS
90.3%
2021 CWE-200 3 PoCs

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVE-2025-2712
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-24354
imgproxy General ⚡ nuclei
5.3
MEDIUM
EPSS
2.2%
2025 CWE-918 1 PoC

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.

CVE-2025-46554
xwiki-platform General ⚡ nuclei
5.3
MEDIUM
EPSS
0.1%
2025 CWE-862 0 PoCs

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki attachment REST endpoint. There is no filtering for the results depending on current user rights, meaning an unauthenticated user could exploit this even in a private wiki. This issue has been patched in versions 14.10.22, 15.10.12, 16.4.3, and 16.7.0.