3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-6910
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2018 1 PoC

DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

CVE-2018-1000600
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2018 0 PoCs

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVE-2018-19136
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

CVE-2018-2392
SAP Internet Graphics Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2018 1 PoC

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

CVE-2018-19287
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
12.2%
2018 1 PoC

XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

CVE-2018-19751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

CVE-2018-18777
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2018 2 PoCs

Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.

CVE-2018-7490
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2018 2 PoCs

uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

CVE-2018-9161
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
55.1%
2018 2 PoCs

Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.

CVE-2018-20463
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.5%
2018 2 PoCs

An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

CVE-2018-1000533
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2018 0 PoCs

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

CVE-2018-14916
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
67.9%
2018 3 PoCs

LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

CVE-2018-10088
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2018 1 PoC

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CVE-2018-20985
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.9%
2018 0 PoCs

The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.

CVE-2018-14064
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 3 PoCs

The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

CVE-2018-8715
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2018 0 PoCs

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

CVE-2018-1271
Spring Framework Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2018 CWE-22 6 PoCs

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2018-16979
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.7%
2018 0 PoCs

Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

CVE-2018-3810
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2018 6 PoCs

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.

CVE-2018-14931
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
7.0%
2018 1 PoC

An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.