3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-12542
Integrated Lights-out 4 (iLO 4) General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2017 3 PoCs

A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

CVE-2017-16877
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2017 1 PoC

ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

CVE-2017-18505
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2017 0 PoCs

The twitter-plugin plugin before 2.55 for WordPress has XSS.

CVE-2017-18542
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.

CVE-2017-18492
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The contact-form-to-db plugin before 1.5.7 for WordPress has multiple XSS issues.

CVE-2017-1000170
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2017 1 PoC

jqueryFileTree 2.1.5 and older Directory Traversal

CVE-2017-3131
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

CVE-2017-16806
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.5%
2017 1 PoC

The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.

CVE-2017-18493
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The custom-admin-page plugin before 0.1.2 for WordPress has multiple XSS issues.

CVE-2017-5631
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
25.3%
2017 1 PoC

An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

CVE-2017-12138
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.4%
2017 0 PoCs

XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

CVE-2017-3133
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.7%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

CVE-2017-18517
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.

CVE-2017-1000163
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2017 1 PoC

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

CVE-2017-17059
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2017 1 PoC

XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php.

CVE-2017-18532
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The realty plugin before 1.1.0 for WordPress has multiple XSS issues.

CVE-2017-9506
Atlassian OAuth Plugin Web ⚡ nuclei
N/A
UNKNOWN
EPSS
29.0%
2017 3 PoCs

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

CVE-2017-12611
Apache Struts Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2017 3 PoCs

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CVE-2017-18500
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.

CVE-2017-7925
Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
80.4%
2017 CWE-260 0 PoCs

A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The password in configuration file vulnerability was identified, which could lead to a malicious user assuming the identity of a privileged user and gaining access to sensitive information.