2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-13642
Software Genérico Web Windows
8.8
HIGH
EPSS
0.1%
2020 1 PoC

An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for malicious JavaScript to be executed in the victim's browser.

CVE-2020-23592
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2020 2 PoCs

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to default leads to Escalation of Privileges by logging-in with default credentials.

CVE-2020-36842
WPvivid — Backup, Migration & Staging Web Windows
8.8
HIGH
EPSS
48.5%
2020 CWE-434 1 PoC

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This affects versions up to, and including 0.9.35.

CVE-2020-36655
Software Genérico Web
8.8
HIGH
EPSS
4.2%
2020 1 PoC

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

CVE-2020-5421
Spring Framework Web
8.7
HIGH
EPSS
63.8%
2020 7 PoCs

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVE-2020-37090
School ERP Pro Web
8.7
HIGH
EPSS
1.0%
2020 CWE-434 1 PoC

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

CVE-2020-36939
Cassandra Web Web Database
8.7
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

CVE-2020-36907
Aerohive HiveOS Web
8.7
HIGH
EPSS
0.8%
2020 CWE-770 3 PoCs

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.

CVE-2020-36969
M/Monit Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 1 PoC

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.

CVE-2020-11026
WordPress Web Windows
8.7
HIGH
EPSS
4.4%
2020 CWE-707 1 PoC

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2020-37009
MedDream PACS Server Web
8.7
HIGH
EPSS
0.3%
2020 CWE-434 1 PoC

MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system commands with elevated privileges.

CVE-2020-37113
GUnet OpenEclass Web
8.7
HIGH
EPSS
0.2%
2020 CWE-434 1 PoC

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature.

CVE-2020-37116
GUnet OpenEclass Web Database
8.7
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.

CVE-2020-13340
GitLab DevOps Web
8.7
HIGH
EPSS
1.5%
2020 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

CVE-2020-36973
PDW File Browser Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.

CVE-2020-15227
application Web ⚡ nuclei
8.7
HIGH
EPSS
93.8%
2020 CWE-74 4 PoCs

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

CVE-2020-36920
iDS6 DSSPro Digital Signage System Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

CVE-2020-15275
moin-1.9 Web
8.7
HIGH
EPSS
0.4%
2020 CWE-79 1 PoC

MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.

CVE-2020-36950
Laravel Nova DevOps Web
8.7
HIGH
EPSS
0.1%
2020 CWE-770 1 PoC

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.