2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-23042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request.

CVE-2020-29215
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.

CVE-2020-15803
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2020 1 PoC

Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.

CVE-2020-8498
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

CVE-2020-10395
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-group.php by adding a question mark (?) followed by the payload.

CVE-2020-36498
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field.

CVE-2020-28001
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2020 2 PoCs

SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.

CVE-2020-13956
Apache HttpClient Web
N/A
UNKNOWN
EPSS
0.5%
2020 6 PoCs

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVE-2020-9388
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

CVE-2020-26525
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.4%
2020 1 PoC

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

CVE-2020-25005
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-7633
apiconnect-cli-plugins Web
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-8231
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-416 2 PoCs

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVE-2020-23832
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

CVE-2020-12130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.

CVE-2020-35262
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

CVE-2020-36491
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-1951
Apache Tika Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

CVE-2020-13155
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.