2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1473
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2010 2 PoCs

Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2022-0769
Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2022 CWE-89 1 PoC

The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.

CVE-2021-35265
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2021 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.

CVE-2010-1470
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.8%
2010 2 PoCs

Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-25078
Affiliates Manager Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 CWE-79 1 PoC

The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests logged by the click tracking feature, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admin viewing the tracked requests.

CVE-2010-4719
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2010 0 PoCs

Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2022-23944
Apache ShenYu (incubating) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2022 CWE-862 0 PoCs

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

CVE-2010-0972
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2010 0 PoCs

Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-24409
Prismatic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 1 PoC

The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVE-2010-1308
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2010 2 PoCs

Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1858
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.5%
2010 1 PoC

Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2021-25114
Paid Memberships Pro Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2021 CWE-89 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2010-1315
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2010 1 PoC

Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2010-0942
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2010 1 PoC

Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2021-24838
AnyComment Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2021 CWE-601 1 PoC

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

CVE-2010-1719
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2010 2 PoCs

Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-4282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2010 3 PoCs

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

CVE-2021-25067
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2021 CWE-79 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

CVE-2010-1312
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2010 2 PoCs

Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-2045
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2010 2 PoCs

Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.