578 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-13126
Download Manager Web Windows ⚡ nuclei
4.6
MEDIUM
EPSS
1.5%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2024-55417
Software Genérico General ⚡ nuclei
4.3
MEDIUM
EPSS
23.0%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

CVE-2024-34061
changedetection.io Web ⚡ nuclei
4.3
MEDIUM
EPSS
27.7%
2024 CWE-79 0 PoCs

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS vulnerability happens when the user input from a URL or POST data is reflected on the page without being stored, thus allowing the attacker to inject malicious content. This issue has been addressed in version 0.45.22. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-4348
osCommerce General ⚡ nuclei
4.3
MEDIUM
EPSS
15.8%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in osCommerce 4. Affected is an unknown function of the file /catalog/all-products. The manipulation of the argument cat leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262488. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-39887
Apache Superset Web Database ⚡ nuclei
4.3
MEDIUM
EPSS
55.7%
2024 CWE-89 0 PoCs

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named DISALLOWED_SQL_FUNCTIONS has been introduced. This key disallows the use of the following PostgreSQL functions: version, query_to_xml, inet_server_addr, and inet_client_addr. Additional functions can be added to this list for increased protection. This issue affects Apache Superset: be

CVE-2024-3378
Secure Web Gateway General ⚡ nuclei
4.3
MEDIUM
EPSS
3.1%
2024 CWE-79 1 PoC

A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.2.0.160 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259501 was assigned to this vulnerability.

CVE-2024-5936
imartinez/privategpt General ⚡ nuclei
4.3
MEDIUM
EPSS
2.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential phishing attacks, malware distribution, and credential theft.

CVE-2024-7097
WSO2 Open Banking AM General ⚡ nuclei
4.3
MEDIUM
EPSS
26.8%
2024 0 PoCs

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of the self-registration configuration settings. This vulnerability enables malicious actors to create new user accounts without proper authorization. Exploitation of this flaw could allow an attacker to create multiple low-privileged user accounts, gaining unauthorized access to the system. Additionally, continuous exploitation could lead to system resource exhaustion through mass user creation.

CVE-2024-24763
jumpserver Web ⚡ nuclei
4.3
MEDIUM
EPSS
30.7%
2024 CWE-601 0 PoCs

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site scripting attacks. Version 3.10.0 contains a patch for this issue. No known workarounds are available.

CVE-2024-4841
parisneo/lollms-webui Web ⚡ nuclei
4.0
MEDIUM
EPSS
8.5%
2024 CWE-29 0 PoCs

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.

CVE-2024-55416
Software Genérico Web ⚡ nuclei
3.5
LOW
EPSS
1.4%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

CVE-2024-48455
Software Genérico Networking ⚡ nuclei
2.7
LOW
EPSS
63.5%
2024 0 PoCs

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the mode_name, wl_link parameters of the skk_get.cgi component.

CVE-2024-56512
Apache NiFi Web ⚡ nuclei
2.1
LOW
EPSS
40.5%
2024 CWE-638 1 PoC

Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group did not reference any Parameter values, the framework did not check user authorization for the bound Parameter Context. Missing authorization for a bound Parameter Context enabled clients to download non-sensitive Parameter values after creating the Process Group. Creating a new P

CVE-2024-53995
sickchill General ⚡ nuclei
1.9
LOW
EPSS
0.7%
2024 CWE-601 0 PoCs

SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter.

CVE-2024-57050
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2024-0713
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 1 PoC

Sin descripción disponible.

CVE-2024-12760
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2024 0 PoCs

Sin descripción disponible.