2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-18529
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.

CVE-2017-11107
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVE-2017-6090
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2017 4 PoCs

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.

CVE-2023-39108
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2017-18490
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The contact-form-multi plugin before 1.2.1 for WordPress has multiple XSS issues.

CVE-2017-18491
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.

CVE-2017-14651
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2017 1 PoC

WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

CVE-2017-14622
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.

CVE-2014-8739
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2014 3 PoCs

Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

CVE-2015-1503
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2015 3 PoCs

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

CVE-2023-2624
KiviCare Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.3%
2023 2 PoCs

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

CVE-2017-18590
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2017 0 PoCs

The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.

CVE-2017-12635
Apache CouchDB Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2017 5 PoCs

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available i

CVE-2017-18565
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The updater plugin before 1.35 for WordPress has multiple XSS issues.

CVE-2017-18349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.7%
2017 2 PoCs

parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.

CVE-2017-14725
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2017 1 PoC

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

CVE-2017-18598
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2017 1 PoC

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

CVE-2017-17731
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2017 0 PoCs

DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

CVE-2017-18502
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2017 0 PoCs

The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.

CVE-2017-18537
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.