3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0776
hakimel/reveal.js Web ⚡ nuclei
5.3
MEDIUM
EPSS
20.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.

CVE-2022-33901
MultiSafepay plugin for WooCommerce (WordPress plugin) Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
10.2%
2022 0 PoCs

Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.

CVE-2022-25356
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
72.9%
2022 2 PoCs

Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.

CVE-2022-24819
xwiki-platform General ⚡ nuclei
5.3
MEDIUM
EPSS
4.3%
2022 CWE-359 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.

CVE-2022-41697
Ghost Web ⚡ nuclei
5.3
MEDIUM
EPSS
18.6%
2022 CWE-204 1 PoC

A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2024-41955
Mobile-Security-Framework-MobSF Windows ⚡ nuclei
5.2
MEDIUM
EPSS
14.8%
2024 CWE-601 0 PoCs

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.

CVE-2026-27176
MajorDoMo Web ⚡ nuclei
5.1
MEDIUM
EPSS
0.1%
2026 CWE-79 1 PoC

MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The $qry parameter is rendered directly into the HTML page without sanitization via htmlspecialchars(), both in an input field value attribute and in a paragraph element. An attacker can inject arbitrary JavaScript by crafting a URL with malicious content in the qry parameter.

CVE-2025-34032
Jmol Plugin Web ⚡ nuclei
5.1
MEDIUM
EPSS
0.1%
2025 CWE-79 2 PoCs

A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute arbitrary JavaScript in the victim's browser by crafting a malicious link. This can be used to hijack user sessions or manipulate page content. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.

CVE-2025-40630
Icewarp Mail Server Web ⚡ nuclei
5.1
MEDIUM
EPSS
0.8%
2025 CWE-601 2 PoCs

Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e” https://icewarp.domain.com///%2e%2e” . This vulnerability has been tested in Firefox.

CVE-2025-53533
web Web ⚡ nuclei
5.1
MEDIUM
EPSS
0.3%
2025 CWE-79 0 PoCs

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in the class attribute of the body tag without proper sanitization or escaping. An attacker can craft a URL containing an onload attribute that will execute arbitrary JavaScript code in the browser when a victim visits the malicious link. If an attacker sends a crafted pi-hole link

CVE-2023-5244
microweber/microweber Web ⚡ nuclei
5.0
MEDIUM
EPSS
28.9%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

CVE-2021-34630
GTranslate Pro and GTranslate Enterprise Web ⚡ nuclei
5.0
MEDIUM
EPSS
2.7%
2021 CWE-116 0 PoCs

In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below, or in cases where an attacker is able to modify the request en route between the client and the server, or in cases where the user is using an atypical browsing solution.

CVE-2022-0870
gogs/gogs General ⚡ nuclei
5.0
MEDIUM
EPSS
9.1%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2023-34259
Software Genérico General ⚡ nuclei
4.9
MEDIUM
EPSS
93.1%
2023 1 PoC

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

CVE-2024-10708
System Dashboard Web Windows ⚡ nuclei
4.9
MEDIUM
EPSS
8.5%
2024 1 PoC

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

CVE-2023-2009
Pretty Url Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
3.0%
2023 1 PoC

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2224
SEO by 10Web Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
0.9%
2023 2 PoCs

The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-11921
GiveWP Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
2.0%
2024 1 PoC

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2024-31839
Software Genérico General ⚡ nuclei
4.8
MEDIUM
EPSS
84.6%
2024 1 PoC

Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.

CVE-2024-50857
Software Genérico Web ⚡ nuclei
4.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.