2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10398
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-template.php by adding a question mark (?) followed by the payload.

CVE-2020-0550
Snoop Assisted L1D Sampling Advisory Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. The list of affected products is provided in intel-sa-00330: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00330.html

CVE-2020-24104
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.

CVE-2020-15952
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

CVE-2020-28140
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.

CVE-2020-6849
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.3%
2020 2 PoCs

The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.

CVE-2020-10108
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

CVE-2020-13390
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface parameters for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-27533
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

CVE-2020-25538
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2020 2 PoCs

An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.

CVE-2020-13864
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links.

CVE-2020-26511
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.

CVE-2020-17457
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages.

CVE-2020-9033
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.

CVE-2020-22985
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

CVE-2020-28414
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).

CVE-2020-10425
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-glossary.php by adding a question mark (?) followed by the payload.

CVE-2020-13949
Apache Thrift Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

CVE-2020-15307
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.