3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-20982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.0%
2020 0 PoCs

Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.

CVE-2016-1000136
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin heat-trackr v1.0

CVE-2016-6601
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2016 3 PoCs

Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

CVE-2016-10940
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.8%
2016 1 PoC

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

CVE-2016-7834
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
39.5%
2016 0 PoCs

SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-ER585, SNC-ER585H, SNC-ZP550, SNC-ZR550, SNC-EP520, SNC-EP521, SNC-ER520, SNC-ER521, SNC-ER521C network cameras with firmware before Ver.1.86.00 and SONY SNC-CX600, SNC-CX600W, SNC-EB600, SNC-EB600B, SNC-EB602R, SNC-EB630, SNC-EB630B, SNC-EB632R, SNC-EM600, SNC-EM601, SNC-EM602R, SNC-EM602RC, SNC-EM630, SNC-EM631, SNC-EM632R, SNC-EM632RC, SNC-V

CVE-2016-1000129
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2016 0 PoCs

Reflected XSS in wordpress plugin defa-online-image-protector v3.3

CVE-2016-5649
DGN2200 Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2016 CWE-319 2 PoCs

A vulnerability is in the 'BSW_cxttongr.htm' page of the Netgear DGN2200, version DGN2200-V1.0.0.50_7.0.50, and DGND3700, version DGND3700-V1.0.0.17_1.0.17, which can allow a remote attacker to access this page without any authentication. When processed, it exposes the admin password in clear text before it gets redirected to absw_vfysucc.cgia. An attacker can use this password to gain administrator access to the targeted router's web interface.

CVE-2016-8527
Aruba AirWave Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.8%
2016 1 PoC

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into AirWave in the same browser.

CVE-2016-10972
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2016 2 PoCs

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

CVE-2016-1000133
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2016 0 PoCs

Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1

CVE-2016-5674
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.4%
2016 2 PoCs

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

CVE-2016-1000126
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin admin-font-editor v1.8

CVE-2016-1000149
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2016 0 PoCs

Reflected XSS in wordpress plugin simpel-reserveren v3.5.2

CVE-2016-10134
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
86.2%
2016 1 PoC

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

CVE-2016-1000130
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2016 0 PoCs

Reflected XSS in wordpress plugin e-search v1.0

CVE-2016-1000127
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin ajax-random-post v2.00

CVE-2016-10108
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2016 1 PoC

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data.

CVE-2016-1000153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2016 0 PoCs

Reflected XSS in wordpress plugin tidio-gallery v1.1

CVE-2016-1000131
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 1 PoC

Reflected XSS in wordpress plugin e-search v1.0