515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-29200
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 2 PoCs

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

CVE-2021-23241
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
71.1%
2021 0 PoCs

MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.

CVE-2021-24499
Workreap Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2021 CWE-434 7 PoCs

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the uploads/workreap-temp directory. Uploaded files were neither sanitized nor validated, allowing an unauthenticated visitor to upload executable code such as php scripts.

CVE-2021-20323
keycloak-services General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2021 CWE-79 3 PoCs

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

CVE-2021-42192
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
23.5%
2021 1 PoC

Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

CVE-2021-26294
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 1 PoC

An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).

CVE-2021-3007
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.5%
2021 1 PoC

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-33564
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2021 3 PoCs

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.

CVE-2021-24997
WP Guppy Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2021 CWE-862 1 PoC

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user

CVE-2021-42063
SAP Knowledge Warehouse Web ⚡ nuclei
N/A
UNKNOWN
EPSS
40.8%
2021 3 PoCs

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.

CVE-2021-38147
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.7%
2021 1 PoC

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

CVE-2021-42667
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-24170
User Profile Picture Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.1%
2021 CWE-200 1 PoC

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVE-2021-25646
Apache Druid Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2021 12 PoCs

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.

CVE-2021-26247
Cacti Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-79 1 PoC

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

CVE-2021-34805
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 2 PoCs

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

CVE-2021-24237
Realteo Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2021 CWE-79 1 PoC

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.

CVE-2021-26710
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 0 PoCs

A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.

CVE-2021-46068
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.