2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-29047
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.6%
2020 1 PoC

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

CVE-2020-10490
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.

CVE-2020-15721
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.

CVE-2020-8160
MendixSSO Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-79 1 PoC

MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

CVE-2020-28137
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.

CVE-2020-29230
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.

CVE-2020-12842
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.

CVE-2020-36141
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.

CVE-2020-29437
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.

CVE-2020-20977
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.

CVE-2020-25634
3scale-system Web
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-284 1 PoC

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.

CVE-2020-11727
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.

CVE-2020-11710
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 1 PoC

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user de

CVE-2020-1958
Apache Druid Web Windows
N/A
UNKNOWN
EPSS
15.6%
2020 1 PoC

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.

CVE-2020-28188
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 3 PoCs

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVE-2020-26670
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.

CVE-2020-5751
TCExam Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.

CVE-2020-14458
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Mattermost Server before 5.19.0. Attackers can discover private channels via the "get channel by name" API, aka MMSA-2020-0004.

CVE-2020-9016
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

CVE-2020-36496
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.