2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1353
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2010 2 PoCs

Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

CVE-2021-25065
Smash Balloon Social Post Feed Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2021 CWE-79 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

CVE-2010-1532
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 2 PoCs

Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-37291
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
57.5%
2021 1 PoC

An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

CVE-2010-1306
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2010 2 PoCs

Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-2682
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2010 1 PoC

Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2023-39110
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.1%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2010-0467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2010 1 PoC

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.

CVE-2021-26723
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
64.1%
2021 2 PoCs

Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.

CVE-2010-1875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2010 0 PoCs

Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2021-25016
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2021 CWE-79 1 PoC

The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2010-1723
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2010 1 PoC

Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1533
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2010 1 PoC

Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-5028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2010 0 PoCs

SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.

CVE-2010-1718
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2010 1 PoC

Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1314
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2010 2 PoCs

Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2021-24931
Secure Copy Content Protection and Content Locking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-89 2 PoCs

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVE-2010-1955
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2010 2 PoCs

Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-0944
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2010 1 PoC

Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-30213
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2021 0 PoCs

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.