1708 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-7700
phpjs Web
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of phpjs are vulnerable to Prototype Pollution via parse_str.

CVE-2020-6627
Software Genérico Web
9.8
CRITICAL
EPSS
14.1%
2020 3 PoCs

The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

CVE-2020-3251
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
30.7%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-3161
🔥 KEV Cisco IP phone Web Networking
9.8
CRITICAL
EPSS
87.1%
2020 CWE-20 3 PoCs

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVE-2020-36847
Simple File List Web Windows
9.8
CRITICAL
EPSS
89.3%
2020 CWE-434 2 PoCs

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVE-2020-15435
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_start parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9719.

CVE-2020-6141
OS4Ed Web Database
9.8
CRITICAL
EPSS
10.8%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-22452
Software Genérico Web Database
9.8
CRITICAL
EPSS
3.2%
2020 1 PoC

SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

CVE-2020-22819
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2020 2 PoCs

MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.

CVE-2020-3250
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
89.7%
2020 CWE-20 2 PoCs

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-6756
Software Genérico Web
9.8
CRITICAL
EPSS
11.8%
2020 1 PoC

languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.

CVE-2020-37002
Ajenti Web
9.8
CRITICAL
EPSS
0.6%
2020 CWE-78 1 PoC

Ajenti 2.1.36 contains an authentication bypass vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a specified IP and port.

CVE-2020-36719
ListingPro - WordPress Directory & Listing Theme Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.3%
2020 CWE-862 0 PoCs

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily install, activate and deactivate any plugin.

CVE-2020-10823
Software Genérico Web
9.8
CRITICAL
EPSS
9.6%
2020 2 PoCs

A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3).

CVE-2020-6137
OS4Ed Web Database
9.8
CRITICAL
EPSS
0.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-15069
🔥 KEV Software Genérico Web Networking
9.8
CRITICAL
EPSS
82.6%
2020 1 PoC

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

CVE-2020-15429
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9716.

CVE-2020-10257
Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
66.6%
2020 1 PoC

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

CVE-2020-16846
🔥 KEV Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 2 PoCs

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.