515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-50094
Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
88.6%
2023 2 PoCs

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.

CVE-2023-35155
xwiki-platform Web ⚡ nuclei
8.8
HIGH
EPSS
47.0%
2023 CWE-79 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation.

CVE-2023-25194
Apache Kafka Connect API Web ⚡ nuclei
8.8
HIGH
EPSS
94.1%
2023 CWE-502 4 PoCs

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters since Apache Kafka Connect 2.3.0. When configuring the connector via the Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config` property for any of the connector's Kafka clients to "com.sun.security.auth.module.JndiLoginModule", which can be done via the `pro

CVE-2023-30625
rudder-server Database ⚡ nuclei
8.8
HIGH
EPSS
88.2%
2023 CWE-89 1 PoC

rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudder-server prior to 1.3.0-rc.1 are vulnerable to SQL injection. This issue may lead to Remote Code Execution (RCE) due to the `rudder` role in PostgresSQL having superuser permissions by default. Version 1.3.0-rc.1 contains patches for this issue.

CVE-2023-23492
Login with Phone Number WordPress Plugin Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
88.3%
2023 1 PoC

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

CVE-2023-32563
Avalanche General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 0 PoCs

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2023-6933
Better Search Replace Web Windows ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 CWE-502 2 PoCs

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVE-2023-1389
🔥 KEV TP-Link Archer AX21 (AX1800) General ⚡ nuclei
8.8
HIGH
EPSS
93.5%
2023 5 PoCs

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CVE-2023-52251
Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
94.0%
2023 2 PoCs

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

CVE-2023-25573
metersphere Web ⚡ nuclei
8.6
HIGH
EPSS
93.6%
2023 CWE-862 1 PoC

metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-6023
vertaai/modeldb General ⚡ nuclei
8.6
HIGH
EPSS
47.9%
2023 CWE-29 1 PoC

An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.

CVE-2023-0777
modoboa/modoboa General ⚡ nuclei
8.6
HIGH
EPSS
76.2%
2023 CWE-305 2 PoCs

Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-47105
Software Genérico General ⚡ nuclei
8.6
HIGH
EPSS
26.5%
2023 0 PoCs

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

CVE-2023-43795
geoserver General ⚡ nuclei
8.6
HIGH
EPSS
89.5%
2023 CWE-918 0 PoCs

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.

CVE-2023-6360
Software Genérico Web Database Windows ⚡ nuclei
8.6
HIGH
EPSS
84.6%
2023 CWE-89 2 PoCs

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

CVE-2023-26360
🔥 KEV ColdFusion General ⚡ nuclei
8.6
HIGH
EPSS
94.3%
2023 CWE-284 4 PoCs

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

CVE-2023-43662
ShokoServer Web Windows ⚡ nuclei
8.6
HIGH
EPSS
91.9%
2023 CWE-22 0 PoCs

ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ShokoServer as administrator. Any unauthenticated attacker may be able to access sensitive informat

CVE-2023-3722
Aura Device Services General ⚡ nuclei
8.6
HIGH
EPSS
54.6%
2023 CWE-434 1 PoC

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2023-41954
ProfilePress General ⚡ nuclei
8.6
HIGH
EPSS
9.8%
2023 CWE-269 0 PoCs

Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.

CVE-2023-32315
🔥 KEV Openfire Web ⚡ nuclei
8.6
HIGH
EPSS
94.4%
2023 CWE-22 13 PoCs

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched i