2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-18496
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.

CVE-2017-18505
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2017 0 PoCs

The twitter-plugin plugin before 2.55 for WordPress has XSS.

CVE-2017-18542
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.

CVE-2017-18492
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.

CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2017-3131
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

CVE-2017-16806
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.5%
2017 1 PoC

The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.

CVE-2017-18493
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.

CVE-2017-5631
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
25.3%
2017 1 PoC

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

CVE-2023-41599
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2023 1 PoC

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

CVE-2017-12138
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.4%
2017 0 PoCs

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

CVE-2017-3133
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

CVE-2014-4942
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2014 0 PoCs

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

CVE-2014-5111
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
67.7%
2014 1 PoC

Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

CVE-2015-2755
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2015 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

CVE-2017-18517
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.

CVE-2017-17059
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php.

CVE-2017-18532
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The realty plugin before 1.1.0 for WordPress has multiple XSS issues.

CVE-2017-9506
Atlassian OAuth Plugin Web ⚡ nuclei
N/A
UNKNOWN
EPSS
29.0%
2017 3 PoCs

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.