2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1715
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2010 2 PoCs

Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2021-35323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

CVE-2018-5233
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.8%
2018 2 PoCs

Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.

CVE-2021-24987
Social Share, Social Login and Social Comments Plugin – Super Socializer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2021 CWE-79 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

CVE-2018-10383
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 0 PoCs

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

CVE-2018-18778
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 2 PoCs

ACME mini_httpd before 1.30 lets remote users read arbitrary files.

CVE-2021-25299
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.2%
2021 1 PoC

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

CVE-2018-16133
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2018 1 PoC

Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

CVE-2010-1345
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.5%
2010 1 PoC

Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-3377
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
59.2%
2021 0 PoCs

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVE-2010-1304
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 0 PoCs

Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25161
Aruba Instant Access Points Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2018-17207
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2018 1 PoC

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

CVE-2018-17422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2018 0 PoCs

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

CVE-2018-8719
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2018 1 PoC

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

CVE-2021-27670
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 0 PoCs

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVE-2018-14013
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.3%
2018 3 PoCs

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2018-11222
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2018 0 PoCs

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.