2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-5522
HTML5 Video Player Web Database Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.8%
2024 6 PoCs

The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

CVE-2021-21816
D-LINK Web ⚡ nuclei
6.5
MEDIUM
EPSS
77.3%
2021 CWE-200 1 PoC

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2024-21485
dash-core-components Web ⚡ nuclei
6.5
MEDIUM
EPSS
0.9%
2024 CWE-79 5 PoCs

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated attacker who stores a view that exploits this vulnerability could steal the data that's visible to another user who opens that view - not just the data already included on the page, but they could al

CVE-2023-30943
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
26.8%
2023 CWE-73 3 PoCs

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

CVE-2024-50967
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
37.9%
2024 2 PoCs

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

CVE-2023-27163
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
93.3%
2023 23 PoCs

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

CVE-2024-29272
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
89.4%
2024 1 PoC

Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

CVE-2024-7714
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
23.9%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0. Multiple actions are accessible: 'ays_chatgpt_disconnect', 'ays_chatgpt_connect', and 'ays_chatgpt_save_feedback'

CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
20.0%
2024 CWE-862 0 PoCs

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.

CVE-2022-2174
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
27.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.

CVE-2022-2130
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
46.6%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.

CVE-2022-0678
microweber/microweber Web ⚡ nuclei
6.5
MEDIUM
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2023-45826
leantime Web Database ⚡ nuclei
6.5
MEDIUM
EPSS
34.4%
2023 CWE-89 0 PoCs

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability. Confidentiality is impacted as it allows for dumping information from the database. This issue has been addressed in version 2.4-beta-4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2021-26947
Odoo Community Web ⚡ nuclei
6.5
MEDIUM
EPSS
59.3%
2021 CWE-79 0 PoCs

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

CVE-2025-32430
xwiki-platform Web ⚡ nuclei
6.5
MEDIUM
EPSS
0.1%
2025 CWE-79 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabilities, allowing an attacker to execute malicious JavaScript code in the context of the victim's session by getting the victim to visit an attacker-controlled URL. This permits the attacker to perform arbitrary actions using the permissions of the victim. This issue is fixed in versions 16.4.8, 16.10.6 and 17.3.0-rc-1. To workaround the issue,

CVE-2023-6568
mlflow/mlflow Web ⚡ nuclei
6.5
MEDIUM
EPSS
33.4%
2023 CWE-79 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly reflected back to the user without adequate sanitization or escaping, leading to arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in the mlflow/server/auth/__init__.py file, where the user-supplied Content-Type header is directly injected into a Python formatted string and

CVE-2020-36728
Adning Advertising Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
83.1%
2020 CWE-22 1 PoC

The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows unauthenticated attackers to delete arbitrary files which can be used to reset and gain full control of a site.

CVE-2023-1496
imgproxy/imgproxy Web ⚡ nuclei
6.5
MEDIUM
EPSS
39.8%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

CVE-2024-57241
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
24.1%
2024 2 PoCs

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

CVE-2022-2290
zadam/trilium Web ⚡ nuclei
6.4
MEDIUM
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.