1919 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-11728
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
65.9%
2024 CWE-89 1 PoC

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-37728
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
13.5%
2024 0 PoCs

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

CVE-2024-1728
gradio-app/gradio Networking ⚡ nuclei
7.5
HIGH
EPSS
86.5%
2024 CWE-22 1 PoC

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.

CVE-2024-54767
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
7.0%
2024 0 PoCs

An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.

CVE-2024-12025
Collapsing Categories Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
80.6%
2024 CWE-89 1 PoC

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-13322
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
21.5%
2024 CWE-89 0 PoCs

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the 'a_id' parameter in all versions up to, and including, 4.88 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-8859
mlflow/mlflow General ⚡ nuclei
7.5
HIGH
EPSS
25.7%
2024 CWE-29 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.

CVE-2024-27292
docassemble General ⚡ nuclei
7.5
HIGH
EPSS
93.8%
2024 CWE-706 1 PoC

Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.

CVE-2024-0801
Unified Data Protection General ⚡ nuclei
7.5
HIGH
EPSS
49.2%
2024 1 PoC

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

CVE-2024-51739
iTop General ⚡ nuclei
7.5
HIGH
EPSS
31.6%
2024 CWE-200 0 PoCs

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. Users unable to upgrade may overload the dictionary entry `"UI:ResetPwd-Error-WrongLogin"` through an extension and replace it with a generic message.

CVE-2024-10400
Tutor LMS – eLearning and online course solution Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
93.2%
2024 CWE-89 1 PoC

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-41628
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.5%
2024 1 PoC

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

CVE-2024-45293
PhpSpreadsheet Web ⚡ nuclei
7.5
HIGH
EPSS
70.3%
2024 CWE-611 0 PoCs

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload their own Excel (XLSX) sheets, Server files and sensitive information can be disclosed by providing a crafted sheet. The security scan function in src/PhpSpreadsheet/Reader/Security/XmlScanner.php contains a flawed XML encoding check to retrieve the input file's XML encoding in the toUtf8 function. The function searches

CVE-2024-48360
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.0%
2024 1 PoC

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

CVE-2024-32739
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
59.0%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

CVE-2024-53991
discourse Web ⚡ nuclei
7.5
HIGH
EPSS
46.6%
2024 CWE-200 0 PoCs

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the Discourse backup file, the attacker can trick nginx into sending the Discourse backup file with a well crafted request. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. Users unable to upgrade can either 1. Download all local backups on to another storage device, disable the

CVE-2024-21644
pyload General ⚡ nuclei
7.5
HIGH
EPSS
86.5%
2024 CWE-284 1 PoC

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

CVE-2024-2053
Artica Proxy Web ⚡ nuclei
7.5
HIGH
EPSS
40.9%
2024 CWE-23 3 PoCs

The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the "www-data" user.

CVE-2024-9935
PDF Generator for WordPress Elementor Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.8%
2024 CWE-22 3 PoCs

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-24569 may be a duplicate of this issue.