878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29775
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.9%
2022 0 PoCs

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

CVE-2022-29301
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-29272
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2022 0 PoCs

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

CVE-2022-34049
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2022 1 PoC

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

CVE-2022-29298
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 1 PoC

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 5 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-37122
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.9%
2022 3 PoCs

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

CVE-2022-26233
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
70.0%
2022 2 PoCs

Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

CVE-2022-48165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.3%
2022 0 PoCs

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

CVE-2022-31854
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2022 3 PoCs

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CVE-2022-25061
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2022 1 PoC

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

CVE-2022-38322
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2022-25082
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2022 0 PoCs

TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-29299
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2022 0 PoCs

Sin descripción disponible.

CVE-2000-0114
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2000 4 PoCs

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

CVE-2006-3392
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2006 9 PoCs

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.