2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-4380
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Web Windows ⚡ nuclei
8.1
HIGH
EPSS
16.5%
2025 CWE-98 1 PoC

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site.

CVE-2017-9805
🔥 KEV Apache Struts Web ⚡ nuclei
8.1
HIGH
EPSS
94.3%
2017 16 PoCs

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVE-2017-17562
🔥 KEV Software Genérico Web ⚡ nuclei
8.1
HIGH
EPSS
94.3%
2017 9 PoCs

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

CVE-2017-12615
🔥 KEV Apache Tomcat Web Windows ⚡ nuclei
8.1
HIGH
EPSS
94.2%
2017 14 PoCs

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2025-48954
discourse Web ⚡ nuclei
8.1
HIGH
EPSS
10.1%
2025 CWE-79 0 PoCs

Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, have the content security policy enabled.

CVE-2017-12617
🔥 KEV Apache Tomcat Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2017 18 PoCs

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2025-2563
User Registration & Membership Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.9%
2025 2 PoCs

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

CVE-2025-2636
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
8.1
HIGH
EPSS
9.6%
2025 CWE-22 0 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file types can be uploaded and included, or are already present on the filesystem locally. There are currently no known v

CVE-2023-5815
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News Web Windows ⚡ nuclei
8.1
HIGH
EPSS
49.2%
2023 CWE-98 1 PoC

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code ex

CVE-2024-10516
Swift Performance Lite Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.8%
2024 CWE-22 1 PoC

The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2021-23394
studio-42/elfinder Web ⚡ nuclei
8.1
HIGH
EPSS
76.8%
2021 1 PoC

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVE-2024-41107
Apache CloudStack Web Cloud ⚡ nuclei
8.1
HIGH
EPSS
92.0%
2024 CWE-290 1 PoC

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication by submitting a spoofed SAML response with no signature and known or guessed username and other user details of a SAML-enabled CloudStack user-account. In such environments, this can result in a complete compromise of the resources owned and/or accessible by a SAML enabled user-account. Affected users are recommended to disable the SAML

CVE-2024-3656
Software Genérico Web ⚡ nuclei
8.1
HIGH
EPSS
89.7%
2024 CWE-200 1 PoC

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

CVE-2018-11776
🔥 KEV Apache Struts Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2018 23 PoCs

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CVE-2023-4220
Chamilo Web ⚡ nuclei
8.1
HIGH
EPSS
93.2%
2023 CWE-434 28 PoCs

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CVE-2024-10783
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.4%
2024 CWE-862 0 PoCs

The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it possible for unauthenticated attackers to log in as an administrator on instances where MainWP Child is not yet connected to the MainWP Dashboard. IMPORTANT: this only affects sites who have MainWP Child installed and have not yet connected to the MainWP Dashboard, and do not have the

CVE-2024-38473
Apache HTTP Server Web ⚡ nuclei
8.1
HIGH
EPSS
88.4%
2024 CWE-116 2 PoCs

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVE-2023-6634
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows ⚡ nuclei
8.1
HIGH
EPSS
91.3%
2023 CWE-88 2 PoCs

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVE-2021-39165
Cachet Web Database ⚡ nuclei
8.1
HIGH
EPSS
89.4%
2021 CWE-287 2 PoCs

Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.