2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-25955
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.

CVE-2020-35314
Software Genérico Web
N/A
UNKNOWN
EPSS
42.6%
2020 2 PoCs

A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.

CVE-2020-10249
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BWA DiREX-Pro 1.2181 devices allow full path disclosure via an invalid name array parameter to val_soft.php3.

CVE-2020-5725
Grandstream UCM6200 series Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-89 2 PoCs

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

CVE-2020-15341
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

CVE-2020-23981
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.

CVE-2020-10483
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

CVE-2020-27885
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.

CVE-2020-17533
Apache Accumulo Web
N/A
UNKNOWN
EPSS
5.3%
2020 CWE-252 1 PoC

Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations. Specifically, the return values of the 'canFlush' and 'canPerformSystemActions' security functions are not checked in some instances, therefore allowing an authenticated user with insufficient permissions to perform the following actions: flushing a table, shutting down Accumulo or an individual tablet server, and setting or removing system-wide Accumulo configuration pro

CVE-2020-22839
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 3 PoCs

Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.

CVE-2020-13652
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the login menu.

CVE-2020-5737
Tenable.Sc Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation techniques have been implemented to correct this issue.

CVE-2020-5758
Grandstream UCM6200 Series Web
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-78 1 PoC

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.

CVE-2020-21651
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.

CVE-2020-28903
Software Genérico Web
N/A
UNKNOWN
EPSS
26.3%
2020 2 PoCs

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-7658
meinheld Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing.

CVE-2020-11658
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

CVE-2020-28183
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.