878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-57050
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2021-3152
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2021 0 PoCs

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

CVE-2021-43495
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
54.6%
2021 0 PoCs

AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

CVE-2021-20837
Movable Type General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2021 12 PoCs

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

CVE-2021-28377
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
52.6%
2021 1 PoC

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

CVE-2021-3374
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2021 0 PoCs

Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.

CVE-2021-23241
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2021 0 PoCs

MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.

CVE-2021-45428
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

CVE-2021-46418
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

CVE-2021-20323
keycloak-services General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2021 CWE-79 3 PoCs

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

CVE-2021-34805
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 2 PoCs

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

CVE-2021-43287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVE-2021-29006
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
20.6%
2021 2 PoCs

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

CVE-2021-3378
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

CVE-2014-9618
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2014 2 PoCs

The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.

CVE-2015-5354
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
21.8%
2015 2 PoCs

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-20114
TCExam General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2021 0 PoCs

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

CVE-2021-46417
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2021 4 PoCs

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.