3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2019-18665
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 0 PoCs

The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.

CVE-2019-12985
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

CVE-2019-13396
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2019 2 PoCs

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

CVE-2019-14223
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.3%
2019 1 PoC

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

CVE-2019-14974
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2019 2 PoCs

SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

CVE-2019-3402
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 1 PoC

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVE-2019-8903
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2019 1 PoC

index.js in Total.js Platform before 3.2.3 allows path traversal.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-12988
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2019 1 PoC

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

CVE-2019-14696
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.6%
2019 1 PoC

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2019-12962
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

CVE-2019-20933
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 3 PoCs

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

CVE-2019-6793
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2019 2 PoCs

An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

CVE-2019-9915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.0%
2019 0 PoCs

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

CVE-2019-17503
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2019 1 PoC

An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.

CVE-2019-12314
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2019 2 PoCs

Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.