2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-25990
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-25834
ArcSight Logger Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2020-28956
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.

CVE-2020-23226
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

CVE-2020-11946
Software Genérico Web
N/A
UNKNOWN
EPSS
67.0%
2020 1 PoC

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

CVE-2020-29280
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.

CVE-2020-21516
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

CVE-2020-20946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.

CVE-2020-19282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

CVE-2020-2322
Jenkins Chaos Monkey Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

CVE-2020-16242
Reason S20 Ethernet Switch Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

CVE-2020-15394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
31.4%
2020 1 PoC

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

CVE-2020-25626
Django REST Framework Web
N/A
UNKNOWN
EPSS
0.7%
2020 CWE-20 1 PoC

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a cross-site-scripting (XSS) vulnerability.

CVE-2020-28149
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.

CVE-2020-10444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-article-rated.php by adding a question mark (?) followed by the payload.

CVE-2020-21987
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session.

CVE-2020-26052
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.

CVE-2020-6577
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

CVE-2020-16145
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVE-2020-9346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.