2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-16242
Reason S20 Ethernet Switch Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

CVE-2020-15394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
31.4%
2020 1 PoC

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

CVE-2020-25626
Django REST Framework Web
N/A
UNKNOWN
EPSS
0.7%
2020 CWE-20 1 PoC

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a cross-site-scripting (XSS) vulnerability.

CVE-2020-28149
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.

CVE-2020-10444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-article-rated.php by adding a question mark (?) followed by the payload.

CVE-2020-21987
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session.

CVE-2020-26052
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.

CVE-2020-6577
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

CVE-2020-16145
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVE-2020-9346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.

CVE-2020-25411
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.

CVE-2020-25516
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.

CVE-2020-11979
Apache Ant Web
N/A
UNKNOWN
EPSS
1.1%
2020 6 PoCs

As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

CVE-2020-36489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename information.

CVE-2020-27615
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2020 3 PoCs

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

CVE-2020-17449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHP-Fusion 9.03 allows XSS via the error_log file.

CVE-2020-27691
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

CVE-2020-21808
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

CVE-2020-10432
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload.

CVE-2020-15051
Software Genérico Web Database
N/A
UNKNOWN
EPSS
25.8%
2020 1 PoC

An issue was discovered in Artica Proxy before 4.30.000000. Stored XSS exists via the Server Domain Name, Your Email Address, Group Name, MYSQL Server, Database, MYSQL Username, Group Name, and Task Description fields.