2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10395
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-group.php by adding a question mark (?) followed by the payload.

CVE-2020-8789
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.

CVE-2020-13956
Apache HttpClient Web
N/A
UNKNOWN
EPSS
0.5%
2020 6 PoCs

Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

CVE-2020-9388
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

CVE-2020-26525
Software Genérico Web Database
N/A
UNKNOWN
EPSS
8.4%
2020 1 PoC

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

CVE-2020-25005
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-7633
apiconnect-cli-plugins Web
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-8231
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-416 2 PoCs

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVE-2020-23832
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

CVE-2020-12130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.

CVE-2020-35262
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

CVE-2020-36491
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-1951
Apache Tika Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

CVE-2020-13155
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.

CVE-2020-20640
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVE-2020-5504
Software Genérico Web Database
N/A
UNKNOWN
EPSS
22.4%
2020 3 PoCs

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVE-2020-11753
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).

CVE-2020-23014
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel.