2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-37645
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.8%
2023 0 PoCs

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

CVE-2019-19822
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2019 3 PoCs

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; H

CVE-2020-26153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2020-13937
Apache Kylin Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 3 PoCs

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

CVE-2019-15501
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2019 2 PoCs

Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

CVE-2020-5775
Instructure Canvas Learning Management System (LMS) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.8%
2020 1 PoC

Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.

CVE-2020-6637
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2020 1 PoC

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2019-14205
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2019 2 PoCs

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

CVE-2020-6171
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2019-10232
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 0 PoCs

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

CVE-2020-12259
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.3%
2020 0 PoCs

rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

CVE-2020-8191
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2020 CWE-79 0 PoCs

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

CVE-2020-35847
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2015-1000012
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2015 0 PoCs

Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

CVE-2023-41621
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2023 0 PoCs

A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

CVE-2019-8390
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2019 2 PoCs

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

CVE-2020-19282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

CVE-2023-37629
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2023 3 PoCs

Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."