2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-5412
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 CWE-441 0 PoCs

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

CVE-2023-2309
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.2%
2023 1 PoC

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2019-17232
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2020-15718
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2020 2 PoCs

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.

CVE-2019-14950
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 0 PoCs

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

CVE-2020-10547
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2019-2588
BI Publisher (formerly XML Publisher) Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector:

CVE-2020-27982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.9%
2020 2 PoCs

IceWarp 11.4.5.0 allows XSS via the language parameter.

CVE-2019-1010290
Babel Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.4%
2019 1 PoC

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.

CVE-2020-15500
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.5%
2020 2 PoCs

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

CVE-2020-23517
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

CVE-2019-16997
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2019 0 PoCs

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.

CVE-2020-17526
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2020 0 PoCs

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

CVE-2019-19368
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
75.6%
2019 1 PoC

A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts

CVE-2020-11530
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 2 PoCs

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

CVE-2020-8641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2020 1 PoC

Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.

CVE-2023-34537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2023 1 PoC

A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

CVE-2023-33831
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 4 PoCs

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2019-2767
BI Publisher (formerly XML Publisher) Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
49.9%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of B

CVE-2020-13820
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.1%
2020 2 PoCs

Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.