2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-19751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

CVE-2018-7490
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2018 2 PoCs

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

CVE-2022-2219
Unyson Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2022 CWE-79 1 PoC

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

CVE-2021-24276
Contact Form by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2021 CWE-79 2 PoCs

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2023-2272
Tiempo.com Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-24226
AccessAlly Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-200 1 PoC

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

CVE-2022-2314
VR Calendar Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2022 CWE-78 1 PoC

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

CVE-2018-20463
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.5%
2018 2 PoCs

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

CVE-2018-1000533
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2018 0 PoCs

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

CVE-2018-10088
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2018 1 PoC

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVE-2021-40875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.0%
2021 1 PoC

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CVE-2018-20985
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.9%
2018 0 PoCs

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

CVE-2021-41282
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 2 PoCs

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2018-14064
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 3 PoCs

The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

CVE-2018-8715
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2018 0 PoCs

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

CVE-2018-1271
Spring Framework Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2018 CWE-22 6 PoCs

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2018-16979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.7%
2018 0 PoCs

Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

CVE-2018-3810
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2018 6 PoCs

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.

CVE-2018-11227
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 1 PoC

Monstra CMS 3.0.4 and earlier has XSS via index.php.

CVE-2018-16283
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 4 PoCs

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.