2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29153
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2022 2 PoCs

HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.

CVE-2018-11686
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2018 1 PoC

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

CVE-2021-24875
eCommerce Product Catalog Plugin for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 CWE-79 1 PoC

The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue

CVE-2018-12054
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2018 1 PoC

Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.

CVE-2022-2376
Directorist – WordPress Business Directory Plugin with Classified Ads Listings Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.5%
2022 CWE-862 1 PoC

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

CVE-2018-7314
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.8%
2018 1 PoC

SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429.

CVE-2021-41467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2021 0 PoCs

Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to inject arbitrary web script or HTML via the challenge parameter.

CVE-2018-15917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2018 2 PoCs

Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

CVE-2018-7196
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

CVE-2018-8006
Apache ActiveMQ Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2018 0 PoCs

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

CVE-2018-7700
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 1 PoC

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

CVE-2018-3238
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
30.5%
2018 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete acce

CVE-2018-19752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

CVE-2021-24170
User Profile Picture Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.1%
2021 CWE-200 1 PoC

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVE-2018-20009
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

CVE-2018-7193
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

CVE-2021-24452
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2018-8823
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.1%
2018 1 PoC

modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.

CVE-2021-45793
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 0 PoCs

Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.