2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-24223
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2020 3 PoCs

Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.

CVE-2013-3526
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.

CVE-2015-4127
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

CVE-2020-29279
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.2%
2020 0 PoCs

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

CVE-2019-18957
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.1%
2019 1 PoC

Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

CVE-2020-9376
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 1 PoC

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2019-17231
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2019 0 PoCs

includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-20988
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.

CVE-2020-11710
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 1 PoC

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user de

CVE-2023-3345
LMS by Masteriyo Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.8%
2023 1 PoC

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

CVE-2019-20504
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.8%
2019 0 PoCs

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

CVE-2020-28188
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 3 PoCs

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVE-2020-22165
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2020 0 PoCs

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2019-7219
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2019 1 PoC

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

CVE-2020-35580
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.4%
2020 0 PoCs

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

CVE-2023-5991
Hotel Booking Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

CVE-2019-9912
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2019 2 PoCs

The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

CVE-2020-12262
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

CVE-2020-10548
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.