3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2017-14537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2017 3 PoCs

trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.

CVE-2017-17092
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2017 0 PoCs

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVE-2017-18566
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.

CVE-2017-18501
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2017 0 PoCs

The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.

CVE-2017-3132
Fortinet FortiOS Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
8.8%
2017 2 PoCs

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

CVE-2017-11610
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2017 3 PoCs

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

CVE-2017-17736
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2017 0 PoCs

Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

CVE-2017-12544
System Management Homepage for Windows and Linux Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.9%
2017 1 PoC

A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-5982
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2017 2 PoCs

Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.

CVE-2017-15363
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
61.0%
2017 1 PoC

Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.

CVE-2017-18530
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.

CVE-2017-18536
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.2%
2017 0 PoCs

The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.

CVE-2017-11586
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2017 1 PoC

dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.

CVE-2017-10075
WebCenter Content Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2017 1 PoC

Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized acces

CVE-2017-5983
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
6.4%
2017 2 PoCs

The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

CVE-2017-18557
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.

CVE-2017-11165
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2017 3 PoCs

dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.

CVE-2017-18528
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

CVE-2017-9833
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2017 3 PoCs

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

CVE-2017-12583
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2017 0 PoCs

DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.