2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-18698
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.

CVE-2020-13970
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Shopware before 6.2.3 is vulnerable to a Server-Side Request Forgery (SSRF) in its "Mediabrowser upload by URL" feature. This allows an authenticated user to send HTTP, HTTPS, FTP, and SFTP requests on behalf of the Shopware platform server.

CVE-2020-8823
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.

CVE-2020-10225
Software Genérico Web
N/A
UNKNOWN
EPSS
9.4%
2020 1 PoC

An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.

CVE-2020-7660
serialize-javascript Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

CVE-2020-10413
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/import-html.php by adding a question mark (?) followed by the payload.

CVE-2020-23127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

CVE-2020-15714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-11497
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

CVE-2020-15803
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2020 1 PoC

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

CVE-2020-8498
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

CVE-2020-10395
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-group.php by adding a question mark (?) followed by the payload.

CVE-2020-13956
Apache HttpClient Web
N/A
UNKNOWN
EPSS
0.5%
2020 6 PoCs

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVE-2020-9388
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

CVE-2020-26525
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.4%
2020 1 PoC

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

CVE-2020-25005
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-7633
apiconnect-cli-plugins Web
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-8231
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-416 2 PoCs

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVE-2020-23832
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.