3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2018-11227
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2018 1 PoC

Monstra CMS 3.0.4 and earlier has XSS via index.php.

CVE-2018-16283
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
77.3%
2018 4 PoCs

The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

CVE-2018-20526
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2018 2 PoCs

Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

CVE-2018-18323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.4%
2018 3 PoCs

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

CVE-2018-0127
Cisco RV132W and RV134W Wireless VPN Routers Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2018 CWE-200 0 PoCs

A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examin

CVE-2018-9205
avatar_uploader Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.4%
2018 1 PoC

Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

CVE-2018-12675
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
8.8%
2018 0 PoCs

The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.

CVE-2018-19137
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 0 PoCs

DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.

CVE-2018-19915
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

CVE-2018-11709
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2018 1 PoC

wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.

CVE-2018-7251
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2018 2 PoCs

An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

CVE-2018-17431
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
92.1%
2018 4 PoCs

Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.

CVE-2018-19127
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.8%
2018 1 PoC

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

CVE-2018-19749
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.

CVE-2018-18069
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.2%
2018 1 PoC

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.

CVE-2018-5715
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2018 1 PoC

phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

CVE-2018-10230
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2018 0 PoCs

Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.

CVE-2018-19914
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

CVE-2018-16299
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
82.4%
2018 3 PoCs

The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.