878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-3654
openstack-nova General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.4%
2021 CWE-601 0 PoCs

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

CVE-2023-40779
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
35.9%
2023 2 PoCs

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVE-2021-43496
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
40.2%
2021 0 PoCs

Clustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

CVE-2021-42887
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.3%
2021 0 PoCs

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

CVE-2021-46371
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
26.1%
2021 0 PoCs

antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

CVE-2021-45043
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2021 2 PoCs

HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

CVE-2021-37598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 0 PoCs

WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.

CVE-2021-46419
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.3%
2021 1 PoC

An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.

CVE-2023-38646
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2023 45 PoCs

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

CVE-2021-33564
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2021 3 PoCs

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

CVE-2024-0713
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2021-44848
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.0%
2021 1 PoC

In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on whether the username exists.

CVE-2021-46104
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
19.9%
2021 0 PoCs

An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.

CVE-2021-3223
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2021 0 PoCs

Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.

CVE-2021-33558
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
87.5%
2021 3 PoCs

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

CVE-2023-23063
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
30.4%
2023 0 PoCs

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

CVE-2021-44152
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.7%
2021 1 PoC

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

CVE-2021-32172
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.5%
2021 2 PoCs

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

CVE-2021-3017
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.4%
2021 0 PoCs

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.