3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2024-13126
Download Manager Web Windows ⚡ nuclei
4.6
MEDIUM
EPSS
1.5%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

CVE-2020-7318
ePolicy Orchistrator (ePO) Web ⚡ nuclei
4.6
MEDIUM
EPSS
12.5%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

CVE-2022-29548
Software Genérico Web ⚡ nuclei
4.6
MEDIUM
EPSS
76.4%
2022 3 PoCs

A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2020-5284
next.js General ⚡ nuclei
4.4
MEDIUM
EPSS
83.2%
2020 CWE-23 0 PoCs

Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

CVE-2023-4112
Shuttle Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
15.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235959. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-30534
cacti Web ⚡ nuclei
4.3
MEDIUM
EPSS
54.9%
2023 CWE-502 0 PoCs

Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of insecure deserialization is due to using the unserialize function without sanitizing the user input. Cacti has a “safe” deserialization that attempts to sanitize the content and check for specific values before calling unserialize, but

CVE-2023-4115
Cleaning Business Web ⚡ nuclei
4.3
MEDIUM
EPSS
18.1%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. VDB-235962 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4116
Taxi Booking Web ⚡ nuclei
4.3
MEDIUM
EPSS
22.8%
2023 CWE-79 1 PoC

A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235963. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5375
mosparo/mosparo General ⚡ nuclei
4.3
MEDIUM
EPSS
43.3%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

CVE-2023-3479
hestiacp/hestiacp Web ⚡ nuclei
4.3
MEDIUM
EPSS
23.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

CVE-2023-4168
Adlisting General ⚡ nuclei
4.3
MEDIUM
EPSS
74.7%
2023 CWE-200 2 PoCs

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4113
Service Booking Script Web ⚡ nuclei
4.3
MEDIUM
EPSS
15.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4714
PlayTube General ⚡ nuclei
4.3
MEDIUM
EPSS
90.0%
2023 CWE-200 1 PoC

A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handler. The manipulation leads to information disclosure. The attack may be initiated remotely. The identifier VDB-238577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2822
Ethos Identity General ⚡ nuclei
4.3
MEDIUM
EPSS
83.7%
2023 CWE-79 3 PoCs

A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596.

CVE-2023-45038
Music Station General ⚡ nuclei
4.3
MEDIUM
EPSS
6.9%
2023 CWE-287 0 PoCs

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later

CVE-2023-4111
Bus Reservation System Web ⚡ nuclei
4.3
MEDIUM
EPSS
16.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-23897
Simple Mobile URL Redirect Web ⚡ nuclei
4.3
MEDIUM
EPSS
51.0%
2023 CWE-352 0 PoCs

Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.

CVE-2023-4114
Night Club Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
6.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-55417
Software Genérico General ⚡ nuclei
4.3
MEDIUM
EPSS
23.0%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.