2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-39121
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2023 0 PoCs

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

CVE-2007-5728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2007 0 PoCs

Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.

CVE-2007-2449
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.1%
2007 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

CVE-2014-4539
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

CVE-2014-5187
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2014 0 PoCs

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

CVE-2015-2196
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 0 PoCs

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

CVE-2023-43187
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.7%
2023 0 PoCs

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-28121
WooCommerce Payments WordPress Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2023 CWE-287 8 PoCs

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2023-27641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2023 0 PoCs

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

CVE-2015-6920
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

CVE-2023-40750
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

CVE-2015-5469
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
49.1%
2015 0 PoCs

Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.

CVE-2023-36347
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2023 2 PoCs

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

CVE-2014-9444
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.

CVE-2013-2621
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2013 1 PoC

Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.

CVE-2015-6544
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
27.7%
2015 0 PoCs

Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

CVE-2023-24733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.

CVE-2015-9499
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2015 2 PoCs

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

CVE-2020-13700
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2020 0 PoCs

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.