2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-79 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2015-4062
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.3%
2015 2 PoCs

SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2021-24298
Simple Giveaways – Grow your business, email lists and traffic with contests Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 2 PoCs

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

CVE-2021-33851
WordPress Customize Login Image Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2021 CWE-79 1 PoC

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

CVE-2021-45422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.5%
2021 4 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

CVE-2021-24389
WP Foodbakery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 1 PoC

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-24316
Mediumish Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2021 CWE-79 2 PoCs

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

CVE-2021-36646
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 0 PoCs

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.

CVE-2009-3053
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2009 0 PoCs

Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.

CVE-2009-4202
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2009 0 PoCs

Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.

CVE-2009-2015
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2009 1 PoC

Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2009-3318
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 0 PoCs

Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

CVE-2009-0932
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.6%
2009 1 PoC

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.

CVE-2009-1496
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 1 PoC

Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.

CVE-2009-4223
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2009 1 PoC

PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

CVE-2009-1872
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.9%
2009 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

CVE-2014-6308
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.9%
2014 2 PoCs

Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.

CVE-2015-9312
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2015 0 PoCs

The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.

CVE-2009-2100
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 1 PoC

Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.

CVE-2009-4679
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2009 0 PoCs

Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.