3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2015-2068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.

CVE-2015-2996
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2015 2 PoCs

Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.

CVE-2015-4666
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
16.4%
2015 3 PoCs

Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.

CVE-2015-2080
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2015 4 PoCs

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

CVE-2015-7377
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

CVE-2015-9414
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 1 PoC

The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.

CVE-2015-6477
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2015 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-8350
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.

CVE-2015-4455
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.3%
2015 1 PoC

Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

CVE-2015-8399
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2015 1 PoC

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

CVE-2015-3648
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
51.7%
2015 1 PoC

Directory traversal vulnerability in pages/setup.php in Montala Limited ResourceSpace before 7.2.6727 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the defaultlanguage parameter.

CVE-2015-5471
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
54.0%
2015 2 PoCs

Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.

CVE-2015-4050
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
76.2%
2015 0 PoCs

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVE-2015-20067
WP Attachment Export Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
19.1%
2015 CWE-862 2 PoCs

The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

CVE-2015-5461
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2015 3 PoCs

Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

CVE-2015-5688
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2015 0 PoCs

Directory traversal vulnerability in lib/app/index.js in Geddy before 13.0.8 for Node.js allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.

CVE-2015-8349
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2015 0 PoCs

Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.

CVE-2015-5354
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
21.8%
2015 2 PoCs

Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.

CVE-2015-4062
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
10.3%
2015 2 PoCs

SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2015-9312
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2015 0 PoCs

The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.