2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-7196
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

CVE-2018-8006
Apache ActiveMQ Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2018 0 PoCs

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

CVE-2018-7700
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2018 1 PoC

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

CVE-2018-3238
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
30.5%
2018 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete acce

CVE-2022-0595
Drag and Drop Multiple File Upload – Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2022 CWE-79 1 PoC

The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue

CVE-2021-46072
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

CVE-2022-1054
RSVP and Event Management Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.7%
2022 CWE-862 1 PoC

The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting its entries, and has the export function hooked to the init action. As a result, unauthenticated attackers could call it and retrieve PII such as first name, last name and email address of user registered for events

CVE-2018-19752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

CVE-2021-24170
User Profile Picture Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.1%
2021 CWE-200 1 PoC

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVE-2018-20009
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

CVE-2018-7193
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

CVE-2021-24452
W3 Total Cache Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.7%
2021 CWE-79 1 PoC

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

CVE-2018-8823
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.1%
2018 1 PoC

modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.

CVE-2021-45793
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 0 PoCs

Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

CVE-2018-19892
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2018 0 PoCs

DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.

CVE-2018-11511
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
19.7%
2018 2 PoCs

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

CVE-2021-24762
Perfect Survey Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2021 CWE-89 3 PoCs

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

CVE-2018-20824
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2018 0 PoCs

The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.

CVE-2021-30151
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2021 0 PoCs

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

CVE-2018-17173
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2018 3 PoCs

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.