3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-3831
gnuboard/gnuboard5 Web ⚡ nuclei
7.1
HIGH
EPSS
26.6%
2021 CWE-79 2 PoCs

gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-21315
🔥 KEV systeminformation General ⚡ nuclei
7.1
HIGH
EPSS
94.0%
2021 CWE-78 6 PoCs

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.

CVE-2025-14611
🔥 KEV CentreStack and TrioFox General ⚡ nuclei
7.1
HIGH
EPSS
58.3%
2025 1 PoC

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise.

CVE-2022-0087
keystonejs/keystone Web ⚡ nuclei
7.1
HIGH
EPSS
56.1%
2022 CWE-79 1 PoC

keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2022-45365
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
20.1%
2022 CWE-79 0 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

CVE-2022-0378
microweber/microweber Web ⚡ nuclei
7.1
HIGH
EPSS
7.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-45836
Download Manager Web ⚡ nuclei
7.1
HIGH
EPSS
8.0%
2022 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.

CVE-2022-2756
kareadita/kavita General ⚡ nuclei
7.1
HIGH
EPSS
56.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

CVE-2024-6188
TrackSYS General ⚡ nuclei
6.9
MEDIUM
EPSS
32.3%
2024 CWE-425 2 PoCs

A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269159. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7339
DVR TD-2104TS-CL General ⚡ nuclei
6.9
MEDIUM
EPSS
89.7%
2024 CWE-200 1 PoC

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-9916
UTCMS Web ⚡ nuclei
6.9
MEDIUM
EPSS
83.6%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-9474
🔥 KEV Cloud NGFW Networking Cloud ⚡ nuclei
6.9
MEDIUM
EPSS
94.2%
2024 CWE-78 7 PoCs

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-11238
EKP General ⚡ nuclei
6.9
MEDIUM
EPSS
12.0%
2024 CWE-22 1 PoC

A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11320
Pandora FMS Windows ⚡ nuclei
6.9
MEDIUM
EPSS
92.6%
2024 CWE-77 2 PoCs

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

CVE-2024-8877
Netman 204 Database ⚡ nuclei
6.9
MEDIUM
EPSS
83.8%
2024 CWE-89 2 PoCs

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

CVE-2024-12987
🔥 KEV Vigor2960 General ⚡ nuclei
6.9
MEDIUM
EPSS
79.0%
2024 CWE-78 0 PoCs

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2024-6922
Automation 360 Web ⚡ nuclei
6.9
MEDIUM
EPSS
32.6%
2024 CWE-918 1 PoC

Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web requests from the server.

CVE-2024-5230
FleetCart General ⚡ nuclei
6.9
MEDIUM
EPSS
40.7%
2024 CWE-200 0 PoCs

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-265981 was assigned to this vulnerability.

CVE-2024-51483
changedetection.io General ⚡ nuclei
6.9
MEDIUM
EPSS
39.1%
2024 CWE-22 0 PoCs

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.

CVE-2024-6646
WN604 Web ⚡ nuclei
6.9
MEDIUM
EPSS
91.0%
2024 CWE-200 0 PoCs

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /downloadFile.php of the component Web Interface. The manipulation of the argument file with the input config leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.