3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-45422
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.5%
2021 4 PoCs

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

CVE-2021-24389
WP Foodbakery Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.9%
2021 CWE-79 1 PoC

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-35064
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2021 3 PoCs

KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

CVE-2021-24316
Mediumish Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
57.4%
2021 CWE-79 2 PoCs

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

CVE-2021-36646
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 0 PoCs

A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.

CVE-2009-1558
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2009 0 PoCs

Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.

CVE-2009-3053
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2009 0 PoCs

Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.

CVE-2009-5114
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.5%
2009 0 PoCs

Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.

CVE-2009-5020
Software Genérico Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2009 1 PoC

Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2009-4202
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2009 0 PoCs

Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.

CVE-2009-2015
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2009 1 PoC

Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2009-0545
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2009 2 PoCs

cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

CVE-2009-3318
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 0 PoCs

Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

CVE-2009-0932
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.6%
2009 1 PoC

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.

CVE-2009-0347
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2009 1 PoC

Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.

CVE-2009-1496
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 1 PoC

Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.

CVE-2009-4223
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2009 1 PoC

PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.

CVE-2009-1872
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.9%
2009 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

CVE-2009-2100
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2009 1 PoC

Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.

CVE-2009-4679
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2009 0 PoCs

Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.