2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-34105
srs Web ⚡ nuclei
7.5
HIGH
EPSS
84.8%
2023 CWE-78 0 PoCs

SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots` endpoint containing any commands to be executed as part of the body of the POST request. This issue may lead to Remote Code Execution (RCE). Versions 5.0.157, 5.0-b1, and 6.0.48 contain a fix.

CVE-2024-12025
Collapsing Categories Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
80.6%
2024 CWE-89 1 PoC

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-5003
Active Directory Integration / LDAP Integration Web Windows ⚡ nuclei
7.5
HIGH
EPSS
77.8%
2023 1 PoC

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

CVE-2022-1442
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
74.9%
2022 CWE-862 1 PoC

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

CVE-2023-27639
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
81.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). Only files that can be parsed in XML can be opened. This is exploited in the wild in March 2023.

CVE-2023-5203
WP Sessions Time Monitoring Full Automatic Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
42.9%
2023 1 PoC

The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection techniques, or in some cases an error/union based technique.

CVE-2023-7164
BackWPup Web Windows ⚡ nuclei
7.5
HIGH
EPSS
25.4%
2023 1 PoC

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

CVE-2023-6505
Migrate WordPress Website & Backups Web Windows ⚡ nuclei
7.5
HIGH
EPSS
73.8%
2023 1 PoC

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

CVE-2025-61884
🔥 KEV Oracle Configurator Web Database ⚡ nuclei
7.5
HIGH
EPSS
48.3%
2025 3 PoCs

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2021-21975
🔥 KEV VMware vRealize Operations Web ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2021 6 PoCs

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

CVE-2025-25231
Omnissa Workspace ONE UEM Web ⚡ nuclei
7.5
HIGH
EPSS
4.0%
2025 1 PoC

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.

CVE-2024-6842
mintplex-labs/anything-llm Web ⚡ nuclei
7.5
HIGH
EPSS
70.2%
2024 CWE-306 0 PoCs

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

CVE-2020-14864
🔥 KEV Business Intelligence Enterprise Edition Web Database ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2020 2 PoCs

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts)

CVE-2026-2025
Mail Mint Web Windows ⚡ nuclei
7.5
HIGH
EPSS
28.0%
2026 1 PoC

The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unauthenticated users to call it and retrieve the email addresses of users on the blog

CVE-2025-1323
WP-Recall – Registration, Profile, Commerce & More Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
27.3%
2025 CWE-89 1 PoC

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and including, 16.26.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-1483
mlflow/mlflow Web ⚡ nuclei
7.5
HIGH
EPSS
75.0%
2024 CWE-22 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of '?', an attacker can traverse the server's directory structure. The issue occurs due to insufficient validation of user-supplied input in the server's handlers.

CVE-2020-26073
Cisco Catalyst SD-WAN Manager Web Networking ⚡ nuclei
7.5
HIGH
EPSS
90.9%
2020 CWE-35 0 PoCs

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or

CVE-2024-6049
vsm LTC Time Sync (vTimeSync) Web ⚡ nuclei
7.5
HIGH
EPSS
72.9%
2024 CWE-32 2 PoCs

The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability. By sending a specially crafted HTTP request, an unauthenticated remote attacker could download arbitrary files from the operating system. As a limitation, the exploitation is only possible if the requested file has some file extension, e. g. .exe or .txt.

CVE-2025-1361
IP2Location Country Blocker Web Windows ⚡ nuclei
7.5
HIGH
EPSS
8.3%
2025 CWE-285 0 PoCs

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.