2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-36104
Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
93.1%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

CVE-2024-57727
🔥 KEV Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
94.0%
2024 1 PoC

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

CVE-2024-29868
Apache StreamPipes Web ⚡ nuclei
9.1
CRITICAL
EPSS
78.4%
2024 CWE-338 1 PoC

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CVE-2021-4374
WordPress Automatic Plugin Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
75.0%
2021 CWE-862 0 PoCs

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.

CVE-2021-41097
path Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
11.7%
2021 CWE-1321 1 PoC

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `

CVE-2021-43778
barcode Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2021 CWE-22 2 PoCs

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.

CVE-2020-17519
🔥 KEV Apache Flink Web ⚡ nuclei
9.1
CRITICAL
EPSS
94.3%
2020 CWE-552 14 PoCs

A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.

CVE-2020-24589
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.2%
2020 0 PoCs

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

CVE-2020-26214
alerta Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
88.9%
2020 CWE-287 0 PoCs

In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented in version 8.1.0 that returns HTTP 401 Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients.

CVE-2020-3187
Cisco Adaptive Security Appliance (ASA) Software Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
94.3%
2020 CWE-22 7 PoCs

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and obtain read and delete access to sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences. An exploit could allow the attacker to view or delete arbitrary files on the tar

CVE-2018-13379
🔥 KEV Fortinet FortiOS, FortiProxy Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
94.5%
2018 8 PoCs

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

CVE-2024-32964
lobe-chat Web ⚡ nuclei
9.0
CRITICAL
EPSS
74.1%
2024 CWE-918 0 PoCs

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

CVE-2021-40438
🔥 KEV Apache HTTP Server Web ⚡ nuclei
9.0
CRITICAL
EPSS
94.4%
2021 CWE-918 10 PoCs

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVE-2021-45046
🔥 KEV Apache Log4j Web ⚡ nuclei
9.0
CRITICAL
EPSS
94.3%
2021 CWE-917 11 PoCs

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.

CVE-2025-48828
vBulletin Web ⚡ nuclei
9.0
CRITICAL
EPSS
73.7%
2025 CWE-424 3 PoCs

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

CVE-2020-4427
🔥 KEV Data Risk Manager Web ⚡ nuclei
9.0
CRITICAL
EPSS
92.7%
2020 2 PoCs

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVE-2023-27524
🔥 KEV Apache Superset Web ⚡ nuclei
8.9
HIGH
EPSS
84.0%
2023 CWE-1188 18 PoCs

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `supe

CVE-2026-27483
mindsdb Web ⚡ nuclei
8.8
HIGH
EPSS
18.8%
2026 CWE-22 0 PoCs

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the "Upload File" module, which corresponds to the API endpoint /api/files. Since the multipart file upload does not perform security checks on the uploaded file path, an attacker can perform path traversal by using `../` sequences in the filename field. The file write operation occurs before calling clear_

CVE-2026-22812
opencode Web ⚡ nuclei
8.8
HIGH
EPSS
3.5%
2026 CWE-306 0 PoCs

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

CVE-2023-23492
Login with Phone Number WordPress Plugin Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
88.3%
2023 1 PoC

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.