2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-5191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

CVE-2020-7051
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.

CVE-2020-13422
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

CVE-2020-23342
Software Genérico Web
N/A
UNKNOWN
EPSS
9.2%
2020 2 PoCs

A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

CVE-2020-10449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload.

CVE-2020-23044
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-28580
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
73.4%
2020 1 PoC

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

CVE-2020-8639
Software Genérico Web
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.

CVE-2020-13260
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.

CVE-2020-5513
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

CVE-2020-3626
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables Web
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE-2020-15902
Software Genérico Web
N/A
UNKNOWN
EPSS
42.8%
2020 1 PoC

Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.

CVE-2020-10494
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.

CVE-2020-28970
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)

CVE-2020-8776
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.

CVE-2020-15869
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

CVE-2020-29259
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.

CVE-2020-29233
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.

CVE-2020-23763
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-35313
Software Genérico Web
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.