2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-20183
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.0%
2019 2 PoCs

uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.

CVE-2020-20627
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2020 0 PoCs

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

CVE-2020-35749
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.9%
2020 3 PoCs

Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2.9.3 and earlier for WordPress allows remote attackers to read arbitrary files via the sjb_file parameter to wp-admin/post.php.

CVE-2023-39677
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.2%
2023 1 PoC

MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

CVE-2019-11370
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2019 1 PoC

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

CVE-2020-8772
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 1 PoC

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVE-2019-2578
WebCenter Sites Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2019 1 PoC

Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.6 (Confidential

CVE-2020-12054
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2020 2 PoCs

The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

CVE-2020-11515
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2020 0 PoCs

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).

CVE-2020-5191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

CVE-2019-11869
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.4%
2019 4 PoCs

The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.

CVE-2020-12800
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

CVE-2020-24903
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVE-2019-19134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2019 1 PoC

The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.

CVE-2020-35729
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 4 PoCs

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

CVE-2019-20224
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 2 PoCs

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

CVE-2020-23814
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2020 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.

CVE-2013-1965
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2013 2 PoCs

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

CVE-2015-9323
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2015 0 PoCs

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVE-2020-23697
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2020 0 PoCs

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.