3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2016-10367
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
50.8%
2016 1 PoC

In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.

CVE-2016-1000155
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin wpsolr-search-engine v7.6

CVE-2016-10960
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2016 1 PoC

The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

CVE-2016-1000134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin hdw-tube v1.2

CVE-2016-10368
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2016 1 PoC

Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.

CVE-2016-1000139
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2016 0 PoCs

Reflected XSS in wordpress plugin infusionsoft v1.5.11

CVE-2016-1000143
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin photoxhibit v2.1.8

CVE-2016-1000140
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin new-year-firework v1.1.9

CVE-2016-7552
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2016 0 PoCs

On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

CVE-2016-1000148
Software Genérico Web Cloud Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2016 0 PoCs

Reflected XSS in wordpress plugin s3-video v0.983

CVE-2016-1000152
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.5%
2016 0 PoCs

Reflected XSS in wordpress plugin tidio-form v1.0

CVE-2016-1000154
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
5.8%
2016 0 PoCs

Reflected XSS in wordpress plugin whizz v1.0.7

CVE-2016-1000132
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2016 0 PoCs

Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

CVE-2016-4975
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
73.3%
2016 1 PoC

Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).

CVE-2016-3081
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2016 5 PoCs

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

CVE-2016-0957
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2016 1 PoC

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

CVE-2016-4977
Spring Security OAuth Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2016 1 PoC

When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.

CVE-2016-10973
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2016 1 PoC

The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to BraftonAdminPage.php.

CVE-2016-10924
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2016 3 PoCs

The ebook-download plugin before 1.2 for WordPress has directory traversal.

CVE-2016-1000128
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2016 0 PoCs

Reflected XSS in wordpress plugin anti-plagiarism v3.60