2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-14728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2018 2 PoCs

upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

CVE-2018-12095
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2018 2 PoCs

A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.

CVE-2021-31805
Apache Struts Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 CWE-917 10 PoCs

The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.

CVE-2022-25487
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2022 1 PoC

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

CVE-2018-8033
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2018 1 PoC

In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

CVE-2021-46387
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
33.4%
2021 2 PoCs

ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.

CVE-2018-1000856
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2018 0 PoCs

DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbitrary script can be executed on all users browsers who visit the affected page. This attack appear to be exploitable via Victim must visit the vulnerable page. This vulnerability appears to have been fixed in No fix yet.

CVE-2018-20011
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

CVE-2021-24522
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

CVE-2018-11686
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2018 1 PoC

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

CVE-2021-24875
eCommerce Product Catalog Plugin for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 CWE-79 1 PoC

The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

CVE-2018-12054
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2018 1 PoC

Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.

CVE-2018-7314
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.8%
2018 1 PoC

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

CVE-2021-41467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2021 0 PoCs

Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.

CVE-2018-15917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2018 2 PoCs

Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

CVE-2018-7196
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

CVE-2018-8006
Apache ActiveMQ Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2018 0 PoCs

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

CVE-2018-7700
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 1 PoC

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

CVE-2018-3238
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
30.5%
2018 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete acce