878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-15642
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2019 1 PoC

rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

CVE-2023-43177
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
76.1%
2023 2 PoCs

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

CVE-2019-8451
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2019 4 PoCs

The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

CVE-2019-8982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2019 1 PoC

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

CVE-2020-24550
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2020 1 PoC

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

CVE-2019-8442
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2019 0 PoCs

The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

CVE-2019-8086
Adobe Experience Manager General ⚡ nuclei
N/A
UNKNOWN
EPSS
54.8%
2019 0 PoCs

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVE-2019-16072
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.3%
2019 1 PoC

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

CVE-2019-7275
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.7%
2019 1 PoC

Optergy Proton/Enterprise devices allow Open Redirect.

CVE-2019-9726
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
59.7%
2019 0 PoCs

Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.

CVE-2019-3401
Jira General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.0%
2019 CWE-863 0 PoCs

The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2019-7276
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2019 2 PoCs

Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

CVE-2019-9632
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2019 0 PoCs

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

CVE-2014-3744
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.2%
2014 0 PoCs

Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.

CVE-2014-8676
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2014 3 PoCs

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

CVE-2015-8399
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2015 1 PoC

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

CVE-2019-14312
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
55.6%
2019 1 PoC

Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

CVE-2019-3912
LabKey Server Community Edition General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2019 CWE-601 1 PoC

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

CVE-2019-17662
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2019 11 PoCs

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.