1919 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-21479
SCIMono General ⚡ nuclei
8.1
HIGH
EPSS
78.2%
2021 0 PoCs

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

CVE-2017-12615
🔥 KEV Apache Tomcat Web Windows ⚡ nuclei
8.1
HIGH
EPSS
94.2%
2017 14 PoCs

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2017-17562
🔥 KEV Software Genérico Web ⚡ nuclei
8.1
HIGH
EPSS
94.3%
2017 9 PoCs

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0.

CVE-2017-5521
🔥 KEV Software Genérico Networking ⚡ nuclei
8.1
HIGH
EPSS
93.8%
2017 1 PoC

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery t

CVE-2017-9805
🔥 KEV Apache Struts Web ⚡ nuclei
8.1
HIGH
EPSS
94.3%
2017 16 PoCs

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.

CVE-2017-12617
🔥 KEV Apache Tomcat Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2017 18 PoCs

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVE-2025-4380
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Web Windows ⚡ nuclei
8.1
HIGH
EPSS
16.5%
2025 CWE-98 1 PoC

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases .php files can can be uploaded and included, or already exist on the site.

CVE-2025-3102
OttoKit: All-in-One Automation Platform Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.8%
2025 CWE-697 10 PoCs

The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.

CVE-2025-57808
esphome General ⚡ nuclei
8.1
HIGH
EPSS
4.7%
2025 CWE-303 0 PoCs

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct value. This allows access to web_server functionality (including OTA, if enabled) without knowing any information about the correct username or password. This issue has been patched in version 2025.8.1.

CVE-2025-48954
discourse Web ⚡ nuclei
8.1
HIGH
EPSS
10.1%
2025 CWE-79 0 PoCs

Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting when the content security policy isn't enabled when using social logins. Version 3.5.0.beta6 patches the issue. As a workaround, have the content security policy enabled.

CVE-2025-2563
User Registration & Membership Web Windows ⚡ nuclei
8.1
HIGH
EPSS
87.9%
2025 2 PoCs

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

CVE-2025-40536
🔥 KEV Web Help Desk General ⚡ nuclei
8.1
HIGH
EPSS
68.9%
2025 CWE-693 1 PoC

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

CVE-2025-2636
InstaWP Connect – 1-click WP Staging & Migration Web Windows ⚡ nuclei
8.1
HIGH
EPSS
9.6%
2025 CWE-22 0 PoCs

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file types can be uploaded and included, or are already present on the filesystem locally. There are currently no known v

CVE-2025-3515
Drag and Drop Multiple File Upload for Contact Form 7 Web Windows ⚡ nuclei
8.1
HIGH
EPSS
4.6%
2025 CWE-434 6 PoCs

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly vali

CVE-2018-11776
🔥 KEV Apache Struts Web ⚡ nuclei
8.1
HIGH
EPSS
94.4%
2018 23 PoCs

Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.

CVE-2018-6961
🔥 KEV NSX SD-WAN by VeloCloud Cloud ⚡ nuclei
8.1
HIGH
EPSS
93.6%
2018 3 PoCs

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

CVE-2022-31101
blockwishlist Database ⚡ nuclei
8.1
HIGH
EPSS
53.9%
2022 CWE-89 2 PoCs

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-32819
squirrelly Web ⚡ nuclei
8.0
HIGH
EPSS
89.6%
2021 CWE-200 1 PoC

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

CVE-2025-6204
🔥 KEV DELMIA Apriso General ⚡ nuclei
8.0
HIGH
EPSS
7.2%
2025 CWE-94 0 PoCs

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

CVE-2020-26217
xstream General ⚡ nuclei
8.0
HIGH
EPSS
93.2%
2020 CWE-78 11 PoCs

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.