3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2016-10956
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2016 3 PoCs

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

CVE-2016-1000146
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2016 0 PoCs

Reflected XSS in wordpress plugin pondol-formmail v1.1

CVE-2016-7981
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
43.5%
2016 1 PoC

Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

CVE-2016-9299
Software Genérico DevOps Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2016 5 PoCs

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

CVE-2016-1000137
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2016 0 PoCs

Reflected XSS in wordpress plugin hero-maps-pro v2.1.0

CVE-2016-6195
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.1%
2016 1 PoC

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.

CVE-2016-1000135
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2016 0 PoCs

Reflected XSS in wordpress plugin hdw-tube v1.2

CVE-2016-1000141
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin page-layout-builder v1.9.3

CVE-2016-1000138
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2016 0 PoCs

Reflected XSS in wordpress plugin indexisto v1.0.5

CVE-2016-10976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.

CVE-2016-2389
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
83.7%
2016 4 PoCs

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

CVE-2016-1000142
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.3%
2016 0 PoCs

Reflected XSS in wordpress plugin parsi-font v4.2.5

CVE-2016-3978
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2016 1 PoC

The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."

CVE-2018-16159
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2018 2 PoCs

The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

CVE-2018-5316
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2018 1 PoC

The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

CVE-2018-12998
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
54.1%
2018 2 PoCs

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

CVE-2018-11473
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2018 0 PoCs

Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

CVE-2018-17153
Software Genérico Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2018 2 PoCs

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session

CVE-2018-16716
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2018 0 PoCs

A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

CVE-2018-19458
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2018 2 PoCs

In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.