2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-16283
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 4 PoCs

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

CVE-2022-34590
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2022 0 PoCs

Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.

CVE-2015-8350
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.

CVE-2018-20526
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2018 2 PoCs

Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

CVE-2021-26294
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 1 PoC

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

CVE-2018-18323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.4%
2018 3 PoCs

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

CVE-2021-25646
Apache Druid Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2021 12 PoCs

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

CVE-2018-0127
Cisco RV132W and RV134W Wireless VPN Routers Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2018 CWE-200 0 PoCs

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examin

CVE-2018-9205
avatar_uploader Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.4%
2018 1 PoC

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

CVE-2021-46068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.

CVE-2018-19137
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 0 PoCs

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

CVE-2021-24876
Registrations for the Events Calendar – Event Registration Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVE-2018-19915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

CVE-2018-11709
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2018 1 PoC

wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.

CVE-2021-24236
Imagements Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.1%
2021 CWE-434 1 PoC

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

CVE-2018-7251
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2018 2 PoCs

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

CVE-2018-19127
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.8%
2018 1 PoC

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

CVE-2018-19749
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.

CVE-2014-9180
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2014 1 PoC

Open redirect vulnerability in go.php in Eleanor CMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the QUERY_STRING.

CVE-2013-6281
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "page" parameter.