2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-13640
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.9%
2020 3 PoCs

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

CVE-2019-15043
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2019 2 PoCs

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVE-2020-28185
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.6%
2020 2 PoCs

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

CVE-2020-13405
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2020 2 PoCs

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

CVE-2020-22208
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
32.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2019-9733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2019 2 PoCs

An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the

CVE-2020-25864
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2020 1 PoC

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.

CVE-2019-20141
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.5%
2019 1 PoC

An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.

CVE-2020-1943
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2020 0 PoCs

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

CVE-2020-12256
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.9%
2020 0 PoCs

rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

CVE-2019-3911
LabKey Server Community Edition Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2019 CWE-79 1 PoC

Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.

CVE-2020-9484
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2020 31 PoCs

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore t

CVE-2019-8943
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 6 PoCs

WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.

CVE-2020-29395
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

CVE-2019-15823
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2019 1 PoC

The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.

CVE-2020-13167
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

CVE-2014-4940
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.6%
2014 0 PoCs

Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

CVE-2014-5258
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.2%
2014 1 PoC

Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2014-4561
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2014 0 PoCs

The ultimate-weather plugin 1.0 for WordPress has XSS