2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-19155
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2020 2 PoCs

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

CVE-2020-5769
Teltonika Gateway TRB245 Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.

CVE-2020-6579
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.php in the MailBeez plugin for ZenCart before 3.9.22 allows remote attackers to inject arbitrary web script or HTML via the cloudloader_mode parameter.

CVE-2020-11971
Apache Camel Web
N/A
UNKNOWN
EPSS
9.7%
2020 3 PoCs

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

CVE-2020-23522
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

CVE-2020-19587
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI.

CVE-2020-28415
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28414).

CVE-2020-18701
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

CVE-2020-20988
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.

CVE-2020-23830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.

CVE-2020-13954
Apache CXF Web
N/A
UNKNOWN
EPSS
14.6%
2020 CWE-79 4 PoCs

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

CVE-2020-20269
Software Genérico Web
N/A
UNKNOWN
EPSS
4.3%
2020 1 PoC

A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.

CVE-2020-10394
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-glossary.php by adding a question mark (?) followed by the payload.

CVE-2020-25515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.

CVE-2020-6010
LearnPress Wordpress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
45.5%
2020 1 PoC

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

CVE-2020-19682
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

CVE-2020-20990
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.

CVE-2020-35273
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

CVE-2020-35700
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.