2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-7994
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.php?mainmenu=home page; the (3) note[note] parameter to the /htdocs/admin/dict.php?id=10 page; the (4) zip[MAIN_INFO_SOCIETE_ZIP] or email[mail] parameter to the /htdocs/admin/company.php page; the (5) url[defaulturl], field[defaultkey], or value[defaultvalue] parameter to the /htdocs/admin/defaultvalues.php page; the (6) key[

CVE-2020-11753
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).

CVE-2020-23014
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user session and/or adding new users to the administration panel.

CVE-2020-5780
Icegram Email Subscribers & Newsletters Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.

CVE-2020-26733
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section.

CVE-2020-18324
Software Genérico Web
N/A
UNKNOWN
EPSS
6.7%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

CVE-2020-20908
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field.

CVE-2020-16152
Software Genérico Web
N/A
UNKNOWN
EPSS
84.9%
2020 2 PoCs

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

CVE-2020-21650
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.

CVE-2020-7017
Kibana Web
N/A
UNKNOWN
EPSS
1.2%
2020 CWE-79 3 PoCs

In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.

CVE-2020-9031
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.

CVE-2020-11610
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

CVE-2020-20141
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

CVE-2020-29070
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.

CVE-2020-10473
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-15487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, al

CVE-2020-9334
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-10493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.

CVE-2020-35687
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.