2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-22002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.

CVE-2020-10494
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.

CVE-2020-28970
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)

CVE-2020-8776
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.

CVE-2020-15869
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

CVE-2020-29259
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.

CVE-2020-13620
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration.

CVE-2020-28858
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

CVE-2020-15849
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the applicati

CVE-2020-29233
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.

CVE-2020-23763
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-35313
Software Genérico Web
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.

CVE-2020-23466
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.

CVE-2020-25757
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.

CVE-2020-10503
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.

CVE-2020-9454
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

CVE-2020-35572
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

CVE-2020-9426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

OX Guard 2.10.3 and earlier allows XSS.

CVE-2020-25594
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.