515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-6750
Clone Web Windows ⚡ nuclei
7.5
HIGH
EPSS
41.8%
2023 1 PoC

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

CVE-2023-27639
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
81.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). Only files that can be parsed in XML can be opened. This is exploited in the wild in March 2023.

CVE-2023-0678
phpipam/phpipam Web ⚡ nuclei
7.5
HIGH
EPSS
67.6%
2023 CWE-862 0 PoCs

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-27640
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
81.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). The content of the file is returned with base64 encoding. This is exploited in the wild in March 2023.

CVE-2023-6505
Migrate WordPress Website & Backups Web Windows ⚡ nuclei
7.5
HIGH
EPSS
73.8%
2023 1 PoC

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-33510
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
71.5%
2023 1 PoC

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

CVE-2023-27159
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
80.2%
2023 0 PoCs

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

CVE-2023-32235
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2023 2 PoCs

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.

CVE-2023-35844
Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2023 3 PoCs

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

CVE-2023-27179
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
85.8%
2023 1 PoC

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVE-2023-0126
SonicWall SMA1000 Networking ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2023 CWE-22 0 PoCs

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.

CVE-2023-31478
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
82.6%
2023 0 PoCs

An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.

CVE-2023-37474
copyparty General ⚡ nuclei
7.5
HIGH
EPSS
89.9%
2023 CWE-22 2 PoCs

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-22047
PeopleSoft Enterprise PT PeopleTools Web Database ⚡ nuclei
7.5
HIGH
EPSS
91.6%
2023 2 PoCs

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-31059
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2023 1 PoC

Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.

CVE-2023-34092
vite General ⚡ nuclei
7.5
HIGH
EPSS
44.8%
2023 CWE-50 1 PoC

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3

CVE-2023-6421
Download Manager Web Windows ⚡ nuclei
7.5
HIGH
EPSS
80.6%
2023 2 PoCs

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVE-2023-35843
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.0%
2023 4 PoCs

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

CVE-2023-7165
JetBackup Web Windows ⚡ nuclei
7.5
HIGH
EPSS
31.6%
2023 1 PoC

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.