2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-24712
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.

CVE-2020-35729
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 4 PoCs

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

CVE-2020-8090
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).

CVE-2020-12845
Software Genérico Web
N/A
UNKNOWN
EPSS
7.7%
2020 1 PoC

Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.

CVE-2020-15943
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2020 3 PoCs

An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.

CVE-2020-1913
Hermes Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-195 1 PoC

An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVE-2020-13699
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
72.9%
2020 1 PoC

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.25

CVE-2020-7642
lazysizes Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.

CVE-2020-35589
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims.

CVE-2020-23054
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in NSK User Agent String Switcher Service v0.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the user agent input field.

CVE-2020-35129
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.

CVE-2020-8594
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].

CVE-2020-27197
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.

CVE-2020-11994
Apache Camel Web
N/A
UNKNOWN
EPSS
2.0%
2020 3 PoCs

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

CVE-2020-19626
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.

CVE-2020-12790
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.

CVE-2020-10391
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-article.php by adding a question mark (?) followed by the payload.

CVE-2020-14455
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.

CVE-2020-10429
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-settings.php by adding a question mark (?) followed by the payload.