2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2001-0537
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2001 1 PoC

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2018-5233
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.8%
2018 2 PoCs

Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.

CVE-2021-24987
Social Share, Social Login and Social Comments Plugin – Super Socializer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2021 CWE-79 1 PoC

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.

CVE-2018-10383
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 0 PoCs

Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

CVE-2018-18778
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 2 PoCs

ACME mini_httpd before 1.30 lets remote users read arbitrary files.

CVE-2021-25299
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.2%
2021 1 PoC

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

CVE-2018-16133
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2018 1 PoC

Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

CVE-2011-4336
Wiki CMS Groupware Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2011 1 PoC

Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.

CVE-2021-25082
Popup Builder – Create highly converting, mobile friendly marketing popups. Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
29.7%
2021 CWE-22 1 PoC

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CVE-2023-27922
Newsletter Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2023 0 PoCs

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2021-25161
Aruba Instant Access Points Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 1 PoC

A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2018-17207
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2018 1 PoC

An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

CVE-2018-17422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2018 0 PoCs

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

CVE-2018-8719
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2018 1 PoC

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

CVE-2021-27670
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2021 0 PoCs

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

CVE-2018-14013
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.3%
2018 3 PoCs

Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2018-11222
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2018 0 PoCs

Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

CVE-2021-27309
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2021 0 PoCs

Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.