2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-28911
Software Genérico Web
N/A
UNKNOWN
EPSS
21.4%
2020 2 PoCs

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.

CVE-2020-10502
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.

CVE-2020-5765
Tenable Nessus Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.

CVE-2020-12422
Firefox Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

CVE-2020-11658
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

CVE-2020-28183
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

CVE-2020-10376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.

CVE-2020-14201
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

CVE-2020-11547
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2020 1 PoC

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVE-2020-9520
Micro Focus Vibe. Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.

CVE-2020-10400
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/article-collaboration.php by adding a question mark (?) followed by the payload.

CVE-2020-25613
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack.

CVE-2020-18698
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

CVE-2020-8823
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.

CVE-2020-10225
Software Genérico Web
N/A
UNKNOWN
EPSS
9.4%
2020 1 PoC

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

CVE-2020-23127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

CVE-2020-15714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-11497
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

CVE-2020-15803
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2020 1 PoC

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

CVE-2020-8498
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).