878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2014-3744
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.2%
2014 0 PoCs

Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.

CVE-2014-8676
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2014 3 PoCs

Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

CVE-2015-8399
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2015 1 PoC

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

CVE-2019-14312
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
55.6%
2019 1 PoC

Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

CVE-2019-3912
LabKey Server Community Edition General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2019 CWE-601 1 PoC

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

CVE-2020-10770
keycloak General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 CWE-918 3 PoCs

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

CVE-2019-17662
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2019 11 PoCs

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

CVE-2019-17538
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2019 0 PoCs

Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.

CVE-2019-7315
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2019 1 PoC

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

CVE-2019-16469
Adobe Experience Manager General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.6%
2019 0 PoCs

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVE-2019-18922
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
87.6%
2019 1 PoC

A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.

CVE-2019-18393
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.4%
2019 0 PoCs

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

CVE-2021-3374
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2021 0 PoCs

Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.

CVE-2021-42192
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
23.5%
2021 1 PoC

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

CVE-2023-46574
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

CVE-2023-39141
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 2 PoCs

webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

CVE-2021-46418
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

CVE-2021-20150
Trendnet AC2600 TEW-827DRU General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.6%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

CVE-2021-40960
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.8%
2021 1 PoC

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.