2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-44528
https://github.com/rails/rails Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2021 CWE-601 0 PoCs

A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.

CVE-2010-1314
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2010 2 PoCs

Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2021-24931
Secure Copy Content Protection and Content Locking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.2%
2021 CWE-89 2 PoCs

The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id parameter of the ays_sccp_results_export_file AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an SQL injection.

CVE-2010-1955
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2010 2 PoCs

Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-0944
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2010 1 PoC

Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-30213
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2021 0 PoCs

Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.

CVE-2010-5278
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
18.6%
2010 1 PoC

Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.

CVE-2010-1461
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2010 1 PoC

Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.

CVE-2021-31862
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.3%
2021 2 PoCs

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

CVE-2010-1491
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2010 2 PoCs

Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-2128
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2010 0 PoCs

Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

CVE-2010-1983
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2010 3 PoCs

Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-1081
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2010 1 PoC

Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-33829
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
48.8%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVE-2010-2259
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2010 1 PoC

Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2010 1 PoC

Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25112
WHMCS Bridge Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2021 CWE-79 1 PoC

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2010-3426
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2010 1 PoC

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1535
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 1 PoC

Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-40868
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
27.0%
2021 2 PoCs

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.