2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2020-10549
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2015-9415
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.0%
2015 1 PoC

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

CVE-2023-38040
Revive Adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2023 0 PoCs

A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

CVE-2020-8115
https://github.com/revive-adserver/revive-adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2020 CWE-79 1 PoC

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printed back without proper escaping in a JavaScript context, allowing an attacker to execute arbitrary JS

CVE-2019-12962
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

CVE-2020-15568
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 2 PoCs

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

CVE-2020-7107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2019-20933
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 3 PoCs

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2023-43326
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

CVE-2020-22210
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
43.9%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2019-9915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.0%
2019 0 PoCs

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVE-2020-11546
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 3 PoCs

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

CVE-2020-24912
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
31.9%
2020 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

CVE-2020-8656
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
81.8%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

CVE-2019-17671
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2019 2 PoCs

In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

CVE-2020-15895
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.7%
2020 1 PoC

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

CVE-2020-21998
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2020 1 PoC

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

CVE-2019-16525
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.8%
2019 2 PoCs

An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript code.