2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-17283
Software Genérico Web Networking Database ⚡ nuclei
N/A
UNKNOWN
EPSS
8.2%
2018 0 PoCs

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.

CVE-2022-0346
XML Sitemap Generator for Google Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2022 CWE-79 1 PoC

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

CVE-2021-31856
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2021 1 PoC

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

CVE-2018-17246
Kibana Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2018 CWE-73 2 PoCs

Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVE-2021-24947
RVM – Responsive Vector Maps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2021 CWE-863 1 PoC

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server

CVE-2018-1000671
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2018 0 PoCs

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.

CVE-2018-18570
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.4%
2018 0 PoCs

Planon before Live Build 41 has XSS.

CVE-2021-24165
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-601 1 PoC

In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.

CVE-2018-17082
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2018 2 PoCs

The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c.

CVE-2021-24940
ووکامرس فارسی Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 1 PoC

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue

CVE-2018-7422
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2018 7 PoCs

A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.

CVE-2018-10738
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
66.9%
2018 0 PoCs

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

CVE-2018-11784
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.6%
2018 9 PoCs

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

CVE-2018-7192
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2018 1 PoC

Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.

CVE-2021-24215
Controlled Admin Access Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.6%
2021 CWE-284 1 PoC

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php and /wp-admin/options.php, can lead to a complete compromise of the target resource.

CVE-2018-16288
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.7%
2018 1 PoC

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

CVE-2018-7662
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2018 0 PoCs

Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.

CVE-2021-37538
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2021 1 PoC

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

CVE-2010-2036
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2010 1 PoC

Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1307
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2010 2 PoCs

Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.