878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2012-4982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.9%
2012 0 PoCs

Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the a parameter.

CVE-2015-4632
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.1%
2015 3 PoCs

Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.

CVE-2023-37599
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 1 PoC

An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

CVE-2012-4032
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.3%
2012 1 PoC

Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx.

CVE-2012-4940
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2012 0 PoCs

Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName parameter in a download action to source/loggin/page_log_dwn_file.hsp, or the fileName parameter in (2) an edit action or (3) a delete action to the default URI.

CVE-2024-12760
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 0 PoCs

Sin descripción disponible.

CVE-2015-2166
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.6%
2015 3 PoCs

Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.

CVE-2015-7245
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2015 2 PoCs

Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.

CVE-2023-38433
IP-HE950E General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.2%
2023 0 PoCs

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware ve

CVE-2015-2794
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2015 4 PoCs

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

CVE-2023-39598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.4%
2023 2 PoCs

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

CVE-2023-31465
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2023 1 PoC

An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.

CVE-2023-49438
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

CVE-2014-9614
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2014 1 PoC

The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

CVE-2015-2996
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2015 2 PoCs

Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.

CVE-2015-2863
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2015 1 PoC

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2023-33568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2023 1 PoC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2015-4668
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2015 2 PoCs

Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.