299 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-59716
Software Genérico Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 0 PoCs

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a non-existent user.

CVE-2025-9985
Featured Image from URL (FIFU) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
2.1%
2025 CWE-532 0 PoCs

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

CVE-2025-59474
Jenkins DevOps ⚡ nuclei
5.3
MEDIUM
EPSS
0.1%
2025 0 PoCs

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

CVE-2025-24354
imgproxy General ⚡ nuclei
5.3
MEDIUM
EPSS
2.2%
2025 CWE-918 1 PoC

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.

CVE-2025-71258
FootPrints Web ⚡ nuclei
5.3
MEDIUM
EPSS
2.0%
2025 CWE-918 2 PoCs

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

CVE-2025-27218
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
76.1%
2025 0 PoCs

Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

CVE-2025-30208
vite General ⚡ nuclei
5.3
MEDIUM
EPSS
89.8%
2025 CWE-200 26 PoCs

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or

CVE-2025-10210
ChanCMS Web Database ⚡ nuclei
5.3
MEDIUM
EPSS
0.9%
2025 CWE-89 0 PoCs

A weakness has been identified in yanyutao0402 ChanCMS up to 3.3.0. Impacted is the function Search of the file app/modules/api/service/Api.js. Executing manipulation of the argument key can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-2127
JUX Real Estate Web ⚡ nuclei
5.3
MEDIUM
EPSS
0.3%
2025 CWE-79 2 PoCs

A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-8266
ChanCMS Web ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 CWE-502 0 PoCs

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.3 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2025-4302
Stop User Enumeration Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.1%
2025 1 PoC

The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-authorized users. However, this can be bypassed by URL-encoding the API path.

CVE-2025-56520
Software Genérico Web ⚡ nuclei
5.3
MEDIUM
EPSS
0.1%
2025 0 PoCs

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.

CVE-2025-14155
Premium Addons for Elementor – Powerful Elementor Templates & Widgets Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.7%
2025 CWE-862 1 PoC

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthenticated attackers to view the content of private, draft, and pending templates.

CVE-2025-9808
The Events Calendar Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
1.2%
2025 CWE-200 0 PoCs

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

CVE-2025-2709
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-2712
UFIDA ERP-NC General ⚡ nuclei
5.3
MEDIUM
EPSS
0.2%
2025 CWE-79 0 PoCs

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-24582
12 Step Meeting List General ⚡ nuclei
5.3
MEDIUM
EPSS
6.4%
2025 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.16.5.

CVE-2025-9196
Trinity Audio – Text to Speech AI audio player to convert content into audio Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
0.5%
2025 CWE-200 1 PoC

The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.21.0 via the ~/admin/inc/phpinfo.php file that gets created on install. This makes it possible for unauthenticated attackers to extract sensitive data including configuration data.

CVE-2025-31486
vite Web ⚡ nuclei
5.3
MEDIUM
EPSS
2.5%
2025 CWE-200 3 PoCs

Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than build.assetsInlineLimit (default: 4kB) and when using Vite 6.0+. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 4.5.12, 5.4.17, 6.0.14, 6.1.4, and 6.2.5.

CVE-2025-71259
FootPrints Web ⚡ nuclei
5.3
MEDIUM
EPSS
2.5%
2025 CWE-918 2 PoCs

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of externally supplied resource references to interact with internal services or cause resource exhaustion impacting availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.