2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2016-1000153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2016 0 PoCs

Reflected XSS in wordpress plugin tidio-gallery v1.1

CVE-2023-4284
Post Timeline Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.1%
2023 1 PoC

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2016-1000131
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 1 PoC

Reflected XSS in wordpress plugin e-search v1.0

CVE-2016-10367
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
50.8%
2016 1 PoC

In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.

CVE-2019-12461
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.8%
2019 1 PoC

Web Port 1.19.1 allows XSS via the /log type parameter.

CVE-2016-1000155
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin wpsolr-search-engine v7.6

CVE-2016-10960
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2016 1 PoC

The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

CVE-2016-1000134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin hdw-tube v1.2

CVE-2016-1000139
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2016 0 PoCs

Reflected XSS in wordpress plugin infusionsoft v1.5.11

CVE-2019-16097
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 6 PoCs

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVE-2016-1000143
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin photoxhibit v2.1.8

CVE-2016-1000140
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin new-year-firework v1.1.9

CVE-2019-16996
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2019 0 PoCs

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.

CVE-2016-1000148
Software Genérico Web Cloud Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2016 0 PoCs

Reflected XSS in wordpress plugin s3-video v0.983

CVE-2016-1000152
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.5%
2016 0 PoCs

Reflected XSS in wordpress plugin tidio-form v1.0

CVE-2016-1000154
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2016 0 PoCs

Reflected XSS in wordpress plugin whizz v1.0.7

CVE-2016-1000132
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2016 0 PoCs

Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

CVE-2019-17506
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2019 0 PoCs

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used to control the router remotely.

CVE-2016-4975
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
73.3%
2016 1 PoC

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).