2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24926
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

CVE-2007-4504
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2007 1 PoC

Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.

CVE-2014-9617
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.2%
2014 1 PoC

Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

CVE-2014-8799
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2014 1 PoC

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

CVE-2014-4544
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php.

CVE-2015-8349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2015 0 PoCs

Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.

CVE-2023-36346
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2023 3 PoCs

POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.

CVE-2021-25094
Tatsu Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2021 CWE-306 5 PoCs

The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin. Moreover, there is a race condition in the zip extraction process which makes the shell file live long enough on the filesystem to be callable by an attacker.

CVE-2021-24791
Header Footer Code Manager Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2021 CWE-89 1 PoC

The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

CVE-2021-33904
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.8%
2021 1 PoC

In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.

CVE-2023-0602
Twittee Text Tweet Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

CVE-2021-24946
Modern Events Calendar Lite Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
60.1%
2021 CWE-89 2 PoCs

The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue

CVE-2021-24335
Car Repair Services & Auto Mechanic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
45.4%
2021 CWE-79 1 PoC

The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue

CVE-2021-27519
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2021 1 PoC

A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.

CVE-2021-24849
WCFM Marketplace – Best Multivendor Marketplace for WooCommerce Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.6%
2021 CWE-89 1 PoC

The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

CVE-2021-24278
Redirection for Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2021 CWE-863 1 PoC

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

CVE-2021-38540
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2021 CWE-269 1 PoC

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVE-2021-46069
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in login panel.

CVE-2021-46071
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login panel.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].