2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-35151
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

CVE-2020-24601
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page

CVE-2020-25270
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.

CVE-2020-23041
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` exception-handling. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request.

CVE-2020-12683
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Katyshop2 before 2.12 has multiple stored XSS issues.

CVE-2020-25343
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php

CVE-2020-28578
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
58.5%
2020 1 PoC

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.

CVE-2020-8818
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

CVE-2020-13168
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

CVE-2020-35252
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.

CVE-2020-26107
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

CVE-2020-5306
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.

CVE-2020-10454
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/sitemap-generator.php by adding a question mark (?) followed by the payload.

CVE-2020-5809
Umbraco CMS Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.

CVE-2020-19639
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI.

CVE-2020-10459
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.

CVE-2020-10946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-28856
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

CVE-2020-35853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. Each time a user visits that URL, the XSS triggers and the attacker can be able to steal the cookie according to the crafted payload.

CVE-2020-10667
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version.