878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-24367
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2023 0 PoCs

Sin descripción disponible.

CVE-2023-26258
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2023 5 PoCs

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE-2019-9757
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.1%
2019 2 PoCs

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualization-exportPDF.view allows local files to be read.

CVE-2019-8446
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 CWE-863 2 PoCs

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2023-45852
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

CVE-2023-45542
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
43.3%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVE-2019-15859
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2019 1 PoC

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

CVE-2019-13101
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2019 1 PoC

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

CVE-2019-19411
USG9500 General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2019 0 PoCs

USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit this vulnerability to cause the value of the confidentiality associated with its use to be diminished.

CVE-2019-18665
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 0 PoCs

The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.

CVE-2019-8903
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2019 1 PoC

index.js in Total.js Platform before 3.2.3 allows path traversal.

CVE-2023-35813
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 2 PoCs

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

CVE-2019-12314
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2019 2 PoCs

Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.

CVE-2019-7254
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2019 1 PoC

Linear eMerge E3-Series devices allow File Inclusion.

CVE-2019-12583
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
59.1%
2019 1 PoC

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

CVE-2019-11013
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2019 2 PoCs

Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

CVE-2019-15642
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2019 1 PoC

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

CVE-2023-43177
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
76.1%
2023 2 PoCs

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

CVE-2019-8451
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2019 4 PoCs

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

CVE-2019-8982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2019 1 PoC

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.