2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-23830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.

CVE-2020-9003
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-13954
Apache CXF Web
N/A
UNKNOWN
EPSS
14.6%
2020 CWE-79 4 PoCs

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

CVE-2020-20269
Software Genérico Web
N/A
UNKNOWN
EPSS
4.3%
2020 1 PoC

A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.

CVE-2020-10394
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-glossary.php by adding a question mark (?) followed by the payload.

CVE-2020-25515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http://<site>/lms/index.php?page=books.

CVE-2020-6010
LearnPress Wordpress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
45.5%
2020 1 PoC

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

CVE-2020-10985
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.

CVE-2020-19682
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

CVE-2020-20990
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.

CVE-2020-35273
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.

CVE-2020-35700
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote authenticated attackers to execute arbitrary SQL commands via the sort_order parameter against the /ajax/form/widget-settings endpoint.

CVE-2020-10451
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-user.php by adding a question mark (?) followed by the payload.

CVE-2020-5777
MAGMI Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.7%
2020 1 PoC

MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.

CVE-2020-36552
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.

CVE-2020-6956
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp.

CVE-2020-35849
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view the Summary field of private issues, as well as bugnotes revisions, gaining access to potentially confidential information via the bugnote_id parameter.

CVE-2020-10480
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.

CVE-2020-11548
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.7%
2020 1 PoC

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

CVE-2020-35452
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
10.3%
2020 1 PoC

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow