2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-18020
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

CVE-2020-12058
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.

CVE-2020-13951
Apache OpenMeetings Web
N/A
UNKNOWN
EPSS
73.3%
2020 1 PoC

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

CVE-2020-26554
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

REDDOXX MailDepot 2033 (aka 2.3.3022) allows XSS via an incoming HTML e-mail message.

CVE-2020-23977
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.

CVE-2020-5514
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

CVE-2020-35249
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.

CVE-2020-19288
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.

CVE-2020-25644
wildfly-openssl Web
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-401 1 PoC

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-5191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

CVE-2020-7051
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.

CVE-2020-13422
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

CVE-2020-23342
Software Genérico Web
N/A
UNKNOWN
EPSS
9.2%
2020 2 PoCs

A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

CVE-2020-28580
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
73.4%
2020 1 PoC

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

CVE-2020-8639
Software Genérico Web
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.

CVE-2020-13260
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.

CVE-2020-5513
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

CVE-2020-3626
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables Web
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE-2020-15902
Software Genérico Web
N/A
UNKNOWN
EPSS
42.8%
2020 1 PoC

Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.

CVE-2020-10494
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.