2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-8231
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-416 2 PoCs

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVE-2020-23832
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

CVE-2020-12130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.

CVE-2020-35262
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

CVE-2020-36491
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-1951
Apache Tika Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

CVE-2020-13155
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=clearsystem URI.

CVE-2020-17466
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.

CVE-2020-20640
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.

CVE-2020-5504
Software Genérico Web Database
N/A
UNKNOWN
EPSS
22.4%
2020 3 PoCs

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

CVE-2020-11753
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).

CVE-2020-23014
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel.

CVE-2020-26733
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.

CVE-2020-18324
Software Genérico Web
N/A
UNKNOWN
EPSS
6.7%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

CVE-2020-20908
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field.

CVE-2020-16152
Software Genérico Web
N/A
UNKNOWN
EPSS
84.9%
2020 2 PoCs

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

CVE-2020-21650
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.

CVE-2020-7017
Kibana Web
N/A
UNKNOWN
EPSS
1.2%
2020 CWE-79 3 PoCs

In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.

CVE-2020-9031
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.