2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-22839
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 3 PoCs

Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.

CVE-2020-13652
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the login menu.

CVE-2020-5737
Tenable.Sc Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation techniques have been implemented to correct this issue.

CVE-2020-28037
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
12.7%
2020 1 PoC

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVE-2020-13820
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.1%
2020 2 PoCs

Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

CVE-2020-10548
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-5758
Grandstream UCM6200 Series Web
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-78 1 PoC

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.

CVE-2020-21651
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.

CVE-2020-28903
Software Genérico Web
N/A
UNKNOWN
EPSS
26.3%
2020 2 PoCs

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-7658
meinheld Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing.

CVE-2020-11658
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

CVE-2020-28183
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

CVE-2020-10376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.

CVE-2020-14201
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

CVE-2020-11547
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2020 1 PoC

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVE-2020-10400
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/article-collaboration.php by adding a question mark (?) followed by the payload.

CVE-2020-25613
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.

CVE-2020-18698
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

CVE-2020-8823
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.