2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1474
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2010 2 PoCs

Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-37416
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2021 1 PoC

Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

CVE-2018-5233
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.8%
2018 2 PoCs

Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.

CVE-2021-24987
Social Share, Social Login and Social Comments Plugin – Super Socializer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2021 CWE-79 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

CVE-2018-10383
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 0 PoCs

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

CVE-2018-18778
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 2 PoCs

ACME mini_httpd before 1.30 lets remote users read arbitrary files.

CVE-2021-25299
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.2%
2021 1 PoC

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

CVE-2018-16133
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2018 1 PoC

Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

CVE-2010-4231
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2010 2 PoCs

Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

CVE-2021-45232
Apache APISIX Dashboard Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 CWE-306 13 PoCs

In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.

CVE-2010-1478
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2010 2 PoCs

Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25161
Aruba Instant Access Points Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2018-17207
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2018 1 PoC

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

CVE-2018-17422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2018 0 PoCs

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

CVE-2018-8719
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2018 1 PoC

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

CVE-2021-27670
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 0 PoCs

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVE-2018-14013
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.3%
2018 3 PoCs

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2018-11222
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2018 0 PoCs

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.