2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-2272
Tiempo.com Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2021-24276
Contact Form by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2021 CWE-79 2 PoCs

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-25063
Skins for Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-79 1 PoC

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2014-9615
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php.

CVE-2014-9119
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2014 2 PoCs

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2014-4550
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.

CVE-2015-6477
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2015 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2023-37728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2023 2 PoCs

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2021-24226
AccessAlly Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-200 1 PoC

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

CVE-2021-24370
Fancy Product Designer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2021 CWE-434 4 PoCs

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

CVE-2021-24917
WPS Hide Login Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.4%
2021 CWE-863 4 PoCs

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

CVE-2021-25075
Duplicate Page or Post Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.5%
2021 CWE-862 1 PoC

The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

CVE-2021-37833
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.6%
2021 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.

CVE-2021-27314
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2021 1 PoC

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

CVE-2021-25003
WPCargo Track & Trace DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2021 CWE-94 2 PoCs

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

CVE-2021-38146
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.5%
2021 1 PoC

The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.

CVE-2021-38702
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 3 PoCs

Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.

CVE-2021-45967
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2021 1 PoC

An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.

CVE-2021-24647
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.0%
2021 CWE-287 2 PoCs

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username