3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2025-27223
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
5.5%
2025 1 PoC

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.

CVE-2025-4396
Relevanssi Premium Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
22.0%
2025 CWE-89 0 PoCs

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.

CVE-2025-28228
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
6.3%
2025 1 PoC

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

CVE-2020-14864
🔥 KEV Business Intelligence Enterprise Edition Web Database ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2020 2 PoCs

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts)

CVE-2020-11738
🔥 KEV Software Genérico Web Windows ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2020 3 PoCs

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

CVE-2020-27986
Software Genérico DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2020 0 PoCs

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

CVE-2020-26073
Cisco Catalyst SD-WAN Manager Web Networking ⚡ nuclei
7.5
HIGH
EPSS
90.9%
2020 CWE-35 0 PoCs

A vulnerability in the application data endpoints of Cisco&nbsp;SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to application programmatic interfaces (APIs). An attacker could exploit this vulnerability by sending malicious requests to an API within the affected application. A successful exploit could allow the attacker to conduct directory traversal attacks and gain access to sensitive information including credentials or

CVE-2020-25078
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2020 3 PoCs

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

CVE-2020-3452
🔥 KEV Cisco Adaptive Security Appliance (ASA) Software Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.5%
2020 CWE-20 25 PoCs

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker

CVE-2020-5410
🔥 KEV Spring Cloud Config Web Cloud ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2020 CWE-23 5 PoCs

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

CVE-2018-0296
🔥 KEV Cisco Adaptive Security Appliance unknown Web Networking ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2018 CWE-20 6 PoCs

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affec

CVE-2018-18325
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2018 1 PoC

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CVE-2018-15811
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2018 1 PoC

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVE-2022-1119
Simple File List Web Windows ⚡ nuclei
7.5
HIGH
EPSS
82.3%
2022 CWE-22 3 PoCs

The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/includes/ee-downloader.php file due to missing controls which makes it possible unauthenticated attackers to supply a path to a file that will subsequently be downloaded, in versions up to and including 3.2.7.

CVE-2022-41840
Welcart e-Commerce (WordPress plugin) Web Windows ⚡ nuclei
7.5
HIGH
EPSS
79.4%
2022 CWE-22 0 PoCs

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

CVE-2022-21500
User Management Web Database ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2022 2 PoCs

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should

CVE-2022-38870
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2022 0 PoCs

Free5gc v3.2.1 is vulnerable to Information disclosure.

CVE-2022-47075
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.1%
2022 3 PoCs

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

CVE-2022-44356
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
47.1%
2022 0 PoCs

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

CVE-2022-31474
BackupBuddy General ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2022 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.