2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24169
Advanced Order Export For WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 2 PoCs

This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.

CVE-2021-24406
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2021 CWE-601 1 PoC

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

CVE-2021-25033
WordPress Newsletter Plugin – Noptin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-601 1 PoC

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

CVE-2015-8350
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.

CVE-2021-25864
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
57.0%
2021 0 PoCs

node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.

CVE-2021-31537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2021 1 PoC

SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and /rewe/prod/web/rewe_go_check.php (version and all other parameters).

CVE-2021-24212
WooCommerce Help Scout Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.5%
2021 CWE-434 2 PoCs

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.

CVE-2021-24472
QT KenthaRadio Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2021 CWE-918 1 PoC

The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will have the web server fetch and display the content from any URI, this would allow for SSRF (Server Side Request Forgery) and RFI (Remote File Inclusion) vulnerabilities on the website.

CVE-2021-24495
Marmoset Viewer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.2%
2021 CWE-79 1 PoC

The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter before outputting back in the page, leading to a reflected Cross-Site Scripting issue.

CVE-2021-45811
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

CVE-2021-43510
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 2 PoCs

SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

CVE-2021-24878
SupportCandy – Helpdesk & Support Ticket System Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue

CVE-2023-24735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.1%
2023 0 PoCs

PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

CVE-2021-41649
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 2 PoCs

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

CVE-2021-24827
Asgaros Forum Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2021 CWE-89 1 PoC

The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

CVE-2014-4577
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2014 0 PoCs

Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.

CVE-2015-4455
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.3%
2015 1 PoC

Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

CVE-2023-6065
Quttera Web Malware Scanner Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.5%
2023 2 PoCs

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

CVE-2021-31682
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.1%
2021 1 PoC

The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization.

CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.