2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-17173
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2018 3 PoCs

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

CVE-2018-20608
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.6%
2018 0 PoCs

imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.

CVE-2021-24347
SP Project & Document Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.6%
2021 CWE-178 4 PoCs

The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".

CVE-2018-19386
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.3%
2018 1 PoC

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.

CVE-2013-7091
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2013 2 PoCs

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

CVE-2018-6200
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.7%
2018 1 PoC

vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.

CVE-2018-9118
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.3%
2018 2 PoCs

exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

CVE-2018-6910
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2018 1 PoC

DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

CVE-2021-24498
Calendar Event Multi View Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2021 CWE-79 1 PoC

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

CVE-2018-19136
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

CVE-2023-38194
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.

CVE-2021-26599
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2021 1 PoC

ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

CVE-2018-19287
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.2%
2018 1 PoC

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

CVE-2018-19751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

CVE-2018-7490
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2018 2 PoCs

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

CVE-2018-20463
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.5%
2018 2 PoCs

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

CVE-2018-1000533
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2018 0 PoCs

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

CVE-2018-10088
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2018 1 PoC

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVE-2021-40875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.0%
2021 1 PoC

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CVE-2018-20985
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.9%
2018 0 PoCs

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.