2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-12611
Apache Struts Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2017 3 PoCs

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CVE-2017-18500
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.

CVE-2017-17043
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.0%
2017 2 PoCs

The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.

CVE-2023-49494
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2023 0 PoCs

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

CVE-2017-10974
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2017 2 PoCs

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

CVE-2017-18487
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.

CVE-2017-18494
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.

CVE-2017-16894
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.8%
2017 2 PoCs

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVE-2023-40755
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

CVE-2017-6478
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2017 1 PoC

paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).

CVE-2017-4011
Network Data Loss Prevention (NDLP) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.9%
2017 1 PoC

Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.

CVE-2015-1000010
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.0%
2015 0 PoCs

Remote file download in simple-image-manipulator v1.0 wordpress plugin

CVE-2017-11444
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.3%
2017 0 PoCs

Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.

CVE-2017-1000028
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2017 4 PoCs

Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

CVE-2023-23161
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

CVE-2017-18518
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

CVE-2017-18024
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2017 1 PoC

AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.

CVE-2017-15715
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2017 2 PoCs

In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

CVE-2017-18562
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.

CVE-2017-8046
Pivotal Spring Data REST and Spring Boot Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2017 8 PoCs

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.