2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1953
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2010 1 PoC

Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-24442
Poll, Survey, Questionnaire and Voting system Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.5%
2021 CWE-89 1 PoC

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

CVE-2010-1472
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.8%
2010 2 PoCs

Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-24987
Social Share, Social Login and Social Comments Plugin – Super Socializer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2021 CWE-79 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

CVE-2018-10383
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 0 PoCs

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

CVE-2018-18778
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 2 PoCs

ACME mini_httpd before 1.30 lets remote users read arbitrary files.

CVE-2021-25299
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.2%
2021 1 PoC

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

CVE-2018-16133
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2018 1 PoC

Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

CVE-2010-1340
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2010 1 PoC

Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2015-8562
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2015 14 PoCs

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.

CVE-2021-25161
Aruba Instant Access Points Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2018-17207
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2018 1 PoC

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

CVE-2018-17422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2018 0 PoCs

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

CVE-2018-8719
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2018 1 PoC

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

CVE-2021-27670
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 0 PoCs

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVE-2018-14013
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.3%
2018 3 PoCs

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2018-11222
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2018 0 PoCs

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.

CVE-2018-6605
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2018 1 PoC

SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.