2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-29078
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2022 6 PoCs

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

CVE-2021-33829
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
48.8%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.

CVE-2010-2259
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2010 1 PoC

Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2010 1 PoC

Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25112
WHMCS Bridge Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2021 CWE-79 1 PoC

The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting

CVE-2010-3426
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2010 1 PoC

Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-3002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2021 1 PoC

Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.

CVE-2010-1535
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 1 PoC

Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-40868
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
27.0%
2021 2 PoCs

In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.

CVE-2010-1473
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 2 PoCs

Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1470
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.8%
2010 2 PoCs

Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25078
Affiliates Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 CWE-79 1 PoC

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVE-2010-4719
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2010 0 PoCs

Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2010-0972
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2010 0 PoCs

Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-24409
Prismatic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 1 PoC

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2010-1308
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2010 2 PoCs

Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1858
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.5%
2010 1 PoC

Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2021-25114
Paid Memberships Pro Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2021 CWE-89 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2010-1315
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2010 1 PoC

Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-0942
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2010 1 PoC

Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.