2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-5975
CZ Loan Management Web Database Windows ⚡ nuclei
9.1
CRITICAL
EPSS
43.9%
2024 1 PoC

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2021-41097
path Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
11.7%
2021 CWE-1321 1 PoC

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `

CVE-2024-5315
ERP CMS Web Database ⚡ nuclei
9.1
CRITICAL
EPSS
63.0%
2024 CWE-89 0 PoCs

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

CVE-2023-49785
NextChat Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2023 CWE-918 1 PoC

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may

CVE-2023-47211
OpManager Web ⚡ nuclei
9.1
CRITICAL
EPSS
76.1%
2023 CWE-22 0 PoCs

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

CVE-2021-4374
WordPress Automatic Plugin Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
75.0%
2021 CWE-862 0 PoCs

The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to arbitrarily update the settings of a vulnerable site and ultimately compromise the entire site.

CVE-2024-36104
Apache OFBiz Web ⚡ nuclei
9.1
CRITICAL
EPSS
93.1%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

CVE-2024-3673
Web Directory Free Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
92.2%
2024 2 PoCs

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

CVE-2024-46310
Software Genérico Web ⚡ nuclei
9.1
CRITICAL
EPSS
83.0%
2024 2 PoCs

Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint

CVE-2024-29868
Apache StreamPipes Web ⚡ nuclei
9.1
CRITICAL
EPSS
78.4%
2024 CWE-338 1 PoC

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

CVE-2024-4180
The Events Calendar Web Windows ⚡ nuclei
9.1
CRITICAL
EPSS
42.4%
2024 1 PoC

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

CVE-2021-40438
🔥 KEV Apache HTTP Server Web ⚡ nuclei
9.0
CRITICAL
EPSS
94.4%
2021 CWE-918 10 PoCs

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVE-2025-48828
vBulletin Web ⚡ nuclei
9.0
CRITICAL
EPSS
73.7%
2025 CWE-424 3 PoCs

Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025.

CVE-2020-4427
🔥 KEV Data Risk Manager Web ⚡ nuclei
9.0
CRITICAL
EPSS
92.7%
2020 2 PoCs

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVE-2021-45046
🔥 KEV Apache Log4j Web ⚡ nuclei
9.0
CRITICAL
EPSS
94.3%
2021 CWE-917 11 PoCs

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.

CVE-2024-32964
lobe-chat Web ⚡ nuclei
9.0
CRITICAL
EPSS
74.1%
2024 CWE-918 0 PoCs

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

CVE-2023-27524
🔥 KEV Apache Superset Web ⚡ nuclei
8.9
HIGH
EPSS
84.0%
2023 CWE-1188 18 PoCs

Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `supe

CVE-2026-22812
opencode Web ⚡ nuclei
8.8
HIGH
EPSS
3.5%
2026 CWE-306 0 PoCs

OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is fixed in 1.0.216.

CVE-2020-1956
🔥 KEV Kylin Web ⚡ nuclei
8.8
HIGH
EPSS
93.9%
2020 1 PoC

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

CVE-2020-2036
PAN-OS Web Networking ⚡ nuclei
8.8
HIGH
EPSS
77.6%
2020 CWE-79 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that management web interface could potentially execute arbitrary JavaScript code in the administrator's browser and perform administrative actions. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9.