2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2010-1308
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2010 2 PoCs

Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-1858
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.5%
2010 1 PoC

Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2021-25114
Paid Memberships Pro Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2021 CWE-89 1 PoC

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVE-2010-1315
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2010 1 PoC

Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

CVE-2021-26812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.0%
2021 0 PoCs

Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

CVE-2010-0942
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2010 1 PoC

Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2022-24681
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

CVE-2021-24838
AnyComment Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2021 CWE-601 1 PoC

The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

CVE-2010-1719
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2010 2 PoCs

Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-4282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2010 3 PoCs

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

CVE-2021-25067
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2021 CWE-79 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

CVE-2010-1312
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2010 2 PoCs

Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

CVE-2010-2045
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2010 2 PoCs

Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

CVE-2007-4556
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2007 0 PoCs

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

CVE-2007-0885
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2007 0 PoCs

Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVE-2014-9608
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
25.7%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

CVE-2014-3704
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2014 12 PoCs

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVE-2014-5181
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2014 0 PoCs

Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.

CVE-2015-2807
Software Genérico Web Cloud Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.9%
2015 4 PoCs

Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

CVE-2021-42063
SAP Knowledge Warehouse Web ⚡ nuclei
N/A
UNKNOWN
EPSS
40.8%
2021 3 PoCs

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.