2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2013-2287
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2013 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

CVE-2015-9406
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2015 2 PoCs

Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.

CVE-2020-17505
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2020 2 PoCs

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

CVE-2019-14974
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2019 2 PoCs

SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

CVE-2020-35774
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2020 0 PoCs

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

CVE-2020-15906
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.0%
2020 2 PoCs

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVE-2019-3402
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 1 PoC

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVE-2020-11455
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 2 PoCs

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

CVE-2020-24701
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.9%
2020 3 PoCs

OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

CVE-2020-14413
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2020 0 PoCs

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVE-2020-12832
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2020 0 PoCs

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2020-8615
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2020 2 PoCs

A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

CVE-2019-14696
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.6%
2019 1 PoC

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2020-22840
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
42.7%
2020 2 PoCs

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVE-2020-9425
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.4%
2020 0 PoCs

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

CVE-2020-20300
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
56.1%
2020 0 PoCs

SQL injection vulnerability in the wp_where function in WeiPHP 5.0.