2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10461
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php, via the GET parameter cmt.

CVE-2020-26935
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2020 1 PoC

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

CVE-2020-7014
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-266 1 PoC

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVE-2020-5783
IgniteNet HeliOS GLinq Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.

CVE-2020-21482
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module

CVE-2020-22840
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
42.7%
2020 2 PoCs

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

CVE-2020-28038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

WordPress before 5.5.2 allows stored XSS via post slugs.

CVE-2020-23829
Software Genérico Web
N/A
UNKNOWN
EPSS
2.5%
2020 1 PoC

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

CVE-2020-13925
Apache Kylin Web
N/A
UNKNOWN
EPSS
84.7%
2020 1 PoC

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command remotely. Users of all previous versions after 2.3 should upgrade to 3.1.0.

CVE-2020-25449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.

CVE-2020-25789
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.

CVE-2020-10404
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-field.php by adding a question mark (?) followed by the payload.

CVE-2020-7471
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.4%
2020 6 PoCs

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

CVE-2020-35131
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2020 1 PoC

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

CVE-2020-10485
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.

CVE-2020-10250
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

BWA DiREX-Pro 1.2181 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the PKG parameter to uninstall.php3.

CVE-2020-29603
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter, without having access to them.

CVE-2020-25987
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

CVE-2020-13920
Apache ActiveMQ Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVE-2020-35240
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in "Blog Content" and each time any user will visit the blog, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.