3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-34599
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.5%
2023 3 PoCs

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.

CVE-2023-45878
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2023 9 PoCs

GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined file path. This allows creation of PHP files that permit Remote Code Execution (unauthenticated).

CVE-2023-5974
wpb-show-core Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

CVE-2023-37645
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.8%
2023 0 PoCs

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

CVE-2023-41621
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2023 0 PoCs

A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

CVE-2023-37629
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2023 3 PoCs

Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."

CVE-2023-46455
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
40.1%
2023 0 PoCs

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

CVE-2023-2309
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.2%
2023 1 PoC

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2023-33831
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 4 PoCs

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

CVE-2023-1893
Login Configurator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 2 PoCs

The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.

CVE-2023-3077
MStore API Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.8%
2023 1 PoC

The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the plugins' pro features, and uses the woocommerce-appointments plugin.

CVE-2023-1780
Companion Sitemap Generator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
16.0%
2023 1 PoC

The Companion Sitemap Generator WordPress plugin before 4.5.3 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-39007
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2023 1 PoC

/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

CVE-2023-4284
Post Timeline Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.1%
2023 1 PoC

The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-41538
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2023 1 PoC

phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.

CVE-2023-24367
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2023 0 PoCs

Sin descripción disponible.

CVE-2024-57050
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2024-0713
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2024-12760
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 0 PoCs

Sin descripción disponible.