3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2014-9618
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
68.2%
2014 2 PoCs

The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.

CVE-2013-4982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
39.6%
2013 2 PoCs

AVTECH AVN801 DVR has a security bypass via the administration login captcha

CVE-2013-2621
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2013 1 PoC

Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.

CVE-2013-1965
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2013 2 PoCs

Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

CVE-2013-2287
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.0%
2013 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

CVE-2013-3827
Software Genérico DevOps Database ⚡ nuclei
N/A
UNKNOWN
EPSS
86.8%
2013 2 PoCs

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

CVE-2013-3526
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earlier, for WordPress allows remote attackers to inject arbitrary web script or HTML via the aoid parameter.

CVE-2013-5528
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
61.5%
2013 2 PoCs

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

CVE-2013-2248
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2013 3 PoCs

Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.

CVE-2013-7240
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
41.5%
2013 2 PoCs

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

CVE-2013-7285
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.8%
2013 3 PoCs

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVE-2013-4625
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.2%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

CVE-2013-4117
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2013 2 PoCs

Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

CVE-2013-5979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.2%
2013 1 PoC

Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

CVE-2013-7091
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2013 2 PoCs

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

CVE-2013-6281
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "page" parameter.

CVE-2015-2166
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.6%
2015 3 PoCs

Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.

CVE-2015-2807
Software Genérico Web Cloud Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.9%
2015 4 PoCs

Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

CVE-2015-8562
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.9%
2015 14 PoCs

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.

CVE-2015-9480
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.9%
2015 1 PoC

The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.