3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2015-5469
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
49.1%
2015 0 PoCs

Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.

CVE-2015-6544
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
27.7%
2015 0 PoCs

Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

CVE-2015-9499
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2015 2 PoCs

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

CVE-2015-9323
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.4%
2015 0 PoCs

The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

CVE-2015-7245
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2015 2 PoCs

Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.

CVE-2015-2794
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2015 4 PoCs

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

CVE-2015-2863
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
49.0%
2015 1 PoC

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2015-9406
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2015 2 PoCs

Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.

CVE-2015-4668
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2015 2 PoCs

Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.

CVE-2015-9415
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
18.0%
2015 1 PoC

The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

CVE-2015-4127
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2015 2 PoCs

Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

CVE-2015-1579
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2015 2 PoCs

Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

CVE-2015-4694
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.5%
2015 4 PoCs

Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

CVE-2015-1000012
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2015 0 PoCs

Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

CVE-2015-0554
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
38.6%
2015 1 PoC

The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device restart) as demonstrated by a direct request to (1) wlsecurity.html or (2) resetrouter.html.

CVE-2023-2796
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

CVE-2023-37728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2023 2 PoCs

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-50917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2023 3 PoCs

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVE-2023-36346
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2023 3 PoCs

POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.