2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-19625
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2020 0 PoCs

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

CVE-2019-12581
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
35.8%
2019 1 PoC

A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or HTML via the err_msg parameter.

CVE-2020-28871
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 5 PoCs

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVE-2020-26879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.9%
2020 4 PoCs

Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

CVE-2019-18952
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.7%
2019 1 PoC

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

CVE-2020-10546
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-10220
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 4 PoCs

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

CVE-2019-3403
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.8%
2019 CWE-863 1 PoC

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2020-11991
Apache Cocoon Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 0 PoCs

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

CVE-2020-8771
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 1 PoC

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

CVE-2019-9879
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.2%
2019 3 PoCs

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

CVE-2020-7943
Puppet Enterprise 2018.1.x stream Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.4%
2020 CWE-276 1 PoC

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Ent

CVE-2014-1203
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
56.1%
2014 0 PoCs

The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.

CVE-2013-5528
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2013 2 PoCs

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

CVE-2015-4694
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2015 4 PoCs

Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

CVE-2023-5974
wpb-show-core Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

CVE-2020-27481
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.0%
2020 0 PoCs

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

CVE-2020-19295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-27735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
52.8%
2020 1 PoC

An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.

CVE-2019-14530
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.0%
2019 4 PoCs

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.