3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-27320
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
26.7%
2021 2 PoCs

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

CVE-2021-46107
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 0 PoCs

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.

CVE-2021-27964
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2021 1 PoC

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

CVE-2021-45027
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
17.4%
2021 1 PoC

An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.

CVE-2021-28151
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2021 0 PoCs

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

CVE-2021-27905
Apache Solr Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2021 CWE-918 2 PoCs

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

CVE-2021-25281
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 2 PoCs

An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master.

CVE-2021-24213
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2021 CWE-79 2 PoCs

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

CVE-2021-22122
Fortinet FortiWeb Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
55.6%
2021 0 PoCs

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload in different vulnerable API end-points.

CVE-2021-46381
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2021 4 PoCs

Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

CVE-2021-22881
https://github.com/rails/rails Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.5%
2021 CWE-601 0 PoCs

The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. Impacted applications will have allowed hosts with a leading dot. When an allowed host contains a leading dot, a specially crafted `Host` header can be used to redirect to a malicious website.

CVE-2021-42627
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
74.3%
2021 2 PoCs

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

CVE-2021-24285
Car Seller - Auto Classifieds Script Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2021 CWE-89 1 PoC

The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.

CVE-2021-27316
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

CVE-2021-46704
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2021 3 PoCs

In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.

CVE-2021-31856
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2021 1 PoC

A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).

CVE-2021-25104
Ocean Extra Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-79 1 PoC

The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

CVE-2021-22873
https://github.com/revive-adserver/revive-adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
46.2%
2021 CWE-601 2 PoCs

Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when delivering ads. However, third party click tracking via redirects is not a viable option anymore, leading to such open redirect functionality being removed and reclassified as a vulnerability.

CVE-2021-26072
Confluence Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
17.5%
2021 0 PoCs

The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.

CVE-2021-27330
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
24.8%
2021 2 PoCs

Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.