2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-40875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.0%
2021 1 PoC

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can be tested, and in some cases, result in the disclosure of hardcoded credentials, API keys, or other sensitive data.

CVE-2018-20985
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.9%
2018 0 PoCs

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

CVE-2022-34047
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
59.2%
2022 3 PoCs

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].

CVE-2021-38146
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.5%
2021 1 PoC

The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.

CVE-2021-41282
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 2 PoCs

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2018-14064
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 3 PoCs

The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

CVE-2018-8715
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2018 0 PoCs

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

CVE-2018-1271
Spring Framework Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2018 CWE-22 6 PoCs

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2018-16979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.7%
2018 0 PoCs

Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

CVE-2018-3810
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2018 6 PoCs

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.

CVE-2018-11227
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 1 PoC

Monstra CMS 3.0.4 and earlier has XSS via index.php.

CVE-2018-16283
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 4 PoCs

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

CVE-2018-20526
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2018 2 PoCs

Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

CVE-2021-26294
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 1 PoC

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

CVE-2018-18323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.4%
2018 3 PoCs

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

CVE-2021-25646
Apache Druid Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2021 12 PoCs

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

CVE-2018-0127
Cisco RV132W and RV134W Wireless VPN Routers Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2018 CWE-200 0 PoCs

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examin

CVE-2018-9205
avatar_uploader Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.4%
2018 1 PoC

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

CVE-2021-46068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.

CVE-2018-19137
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 0 PoCs

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.