2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2016-1000138
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin indexisto v1.0.5

CVE-2019-5434
Revive Adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.1%
2019 CWE-502 1 PoC

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.

CVE-2016-10976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.

CVE-2019-1010287
Timesheet Next Gen Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 0 PoCs

Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

CVE-2019-8449
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2019 3 PoCs

The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

CVE-2016-1000142
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2016 0 PoCs

Reflected XSS in wordpress plugin parsi-font v4.2.5

CVE-2016-3978
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2016 1 PoC

The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."

CVE-2019-6799
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
76.6%
2019 0 PoCs

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the mysql.allow_local_infile PHP configuration, and the inadvertent ignoring of "options(MYSQLI_OPT_LOCAL_INFILE" calls.

CVE-2018-16159
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2018 2 PoCs

The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2018-5316
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2018 1 PoC

The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

CVE-2018-12998
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2018 2 PoCs

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

CVE-2018-11473
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2018 0 PoCs

Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

CVE-2019-16123
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.7%
2019 1 PoC

In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.

CVE-2018-17153
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2018 2 PoCs

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session

CVE-2018-19458
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2018 2 PoCs

In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.

CVE-2019-17382
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2019 2 PoCs

An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.

CVE-2018-10095
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.5%
2018 2 PoCs

Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.

CVE-2018-16139
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2018 0 PoCs

Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web script or HTML via the db or action parameter to to bin/wxis.exe/bibliopac/.

CVE-2019-17230
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.5%
2019 0 PoCs

includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.