1919 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-4463
Maximo Asset Management General ⚡ nuclei
8.2
HIGH
EPSS
85.8%
2020 1 PoC

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 181484.

CVE-2022-45805
Paytm Payment Gateway Database ⚡ nuclei
8.2
HIGH
EPSS
2.8%
2022 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

CVE-2014-3120
🔥 KEV Software Genérico Database ⚡ nuclei
8.1
HIGH
EPSS
82.6%
2014 4 PoCs

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-4220
Chamilo Web ⚡ nuclei
8.1
HIGH
EPSS
93.2%
2023 CWE-434 28 PoCs

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CVE-2023-6634
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Web Windows ⚡ nuclei
8.1
HIGH
EPSS
91.3%
2023 CWE-88 2 PoCs

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVE-2023-5815
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News Web Windows ⚡ nuclei
8.1
HIGH
EPSS
49.2%
2023 CWE-98 1 PoC

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code ex

CVE-2023-0947
flatpressblog/flatpress General ⚡ nuclei
8.1
HIGH
EPSS
53.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2024-10783
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.4%
2024 CWE-862 0 PoCs

The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in an unconfigured state. This makes it possible for unauthenticated attackers to log in as an administrator on instances where MainWP Child is not yet connected to the MainWP Dashboard. IMPORTANT: this only affects sites who have MainWP Child installed and have not yet connected to the MainWP Dashboard, and do not have the

CVE-2024-38856
🔥 KEV Apache OFBiz Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2024 CWE-863 10 PoCs

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

CVE-2024-3656
Software Genérico Web ⚡ nuclei
8.1
HIGH
EPSS
89.7%
2024 CWE-200 1 PoC

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or system compromise.

CVE-2024-41107
Apache CloudStack Web Cloud ⚡ nuclei
8.1
HIGH
EPSS
92.0%
2024 CWE-290 1 PoC

The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments where SAML authentication is enabled, an attacker that initiates CloudStack SAML single sign-on authentication can bypass SAML authentication by submitting a spoofed SAML response with no signature and known or guessed username and other user details of a SAML-enabled CloudStack user-account. In such environments, this can result in a complete compromise of the resources owned and/or accessible by a SAML enabled user-account. Affected users are recommended to disable the SAML

CVE-2024-43425
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
89.3%
2024 3 PoCs

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

CVE-2024-38473
Apache HTTP Server Web ⚡ nuclei
8.1
HIGH
EPSS
88.4%
2024 CWE-116 2 PoCs

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVE-2024-10516
Swift Performance Lite Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.8%
2024 CWE-22 1 PoC

The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2019-6340
🔥 KEV Drupal Core Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2019 12 PoCs

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you sho

CVE-2021-23394
studio-42/elfinder Web ⚡ nuclei
8.1
HIGH
EPSS
76.8%
2021 1 PoC

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

CVE-2021-41192
redash General ⚡ nuclei
8.1
HIGH
EPSS
79.6%
2021 CWE-1188 0 PoCs

Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. This issue only affects installations where the `REDASH_COOKIE_SECRET or REDASH_SECRET_KEY` environment variables have not been explicitly set. This issue does not affect users of the official Reda

CVE-2021-39165
Cachet Web Database ⚡ nuclei
8.1
HIGH
EPSS
89.4%
2021 CWE-287 2 PoCs

Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability to exfiltrate sensitive data from the database such as administrator's password and session. The original repository of Cachet <https://github.com/CachetHQ/Cachet> is not active, the stable version 2.3.18 and it's developing 2.4 branch is affected.

CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.