3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2015-3337
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2015 4 PoCs

Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

CVE-2015-7297
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2015 5 PoCs

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

CVE-2015-2755
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2015 2 PoCs

Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

CVE-2015-1000010
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.0%
2015 0 PoCs

Remote file download in simple-image-manipulator v1.0 wordpress plugin

CVE-2015-3897
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
54.9%
2015 1 PoC

Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

CVE-2015-1503
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2015 3 PoCs

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

CVE-2015-4074
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.8%
2015 3 PoCs

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

CVE-2015-7823
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.7%
2015 1 PoC

Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.

CVE-2015-4063
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2015-3224
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.3%
2015 5 PoCs

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

CVE-2015-1880
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
59.4%
2015 0 PoCs

Cross-site scripting (XSS) vulnerability in the sslvpn login page in Fortinet FortiOS 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-2067
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
76.4%
2015 1 PoC

Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2015-4414
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.1%
2015 3 PoCs

Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2015-1000005
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2015 0 PoCs

Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin

CVE-2015-8813
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.8%
2015 0 PoCs

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

CVE-2015-4632
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.1%
2015 3 PoCs

Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.

CVE-2015-2196
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 0 PoCs

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

CVE-2015-7780
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
36.2%
2015 0 PoCs

Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

CVE-2015-6920
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.