2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-29395
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

CVE-2020-11455
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 2 PoCs

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

CVE-2020-13167
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

CVE-2020-6808
Firefox Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document. This vulnerability affects Firefox < 74.

CVE-2020-13890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.

CVE-2020-35274
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.

CVE-2020-16608
Software Genérico Web
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

CVE-2020-8151
https://github.com/rails/activeresource Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-200 2 PoCs

There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.

CVE-2020-35418
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.

CVE-2020-15487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, al

CVE-2020-9334
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-10493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.

CVE-2020-35687
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

CVE-2020-12418
Firefox ESR Web
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

CVE-2020-21881
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.

CVE-2020-11662
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.

CVE-2020-11620
Software Genérico Web
N/A
UNKNOWN
EPSS
2.1%
2020 5 PoCs

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

CVE-2020-13806
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has a use-after-free because of JavaScript execution after a deletion or close operation.

CVE-2020-36504
Wp-Pro-Quiz Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-352 2 PoCs

The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog