2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-13920
Apache ActiveMQ Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively becomes a man in the middle and is able to intercept the credentials when an user connects. Upgrade to Apache ActiveMQ 5.15.12.

CVE-2020-35240
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in "Blog Content" and each time any user will visit the blog, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

CVE-2020-20975
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

CVE-2020-10441
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-article-monthly.php by adding a question mark (?) followed by the payload.

CVE-2020-12427
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

CVE-2020-6798
Thunderbird Web
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but is potentially a risk in browser or browser-like contexts. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVE-2020-17521
Apache Groovy Web
N/A
UNKNOWN
EPSS
2.4%
2020 7 PoCs

Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.

CVE-2020-15499
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.

CVE-2020-25890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions

CVE-2020-15944
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 3 PoCs

An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.

CVE-2020-24604
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp

CVE-2020-12245
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVE-2020-35478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.

CVE-2020-7246
Software Genérico Web
N/A
UNKNOWN
EPSS
90.4%
2020 9 PoCs

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

CVE-2020-20285
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2020 0 PoCs

There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php

CVE-2020-10416
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/kb-backup.php by adding a question mark (?) followed by the payload.

CVE-2020-8286
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-295 4 PoCs

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVE-2020-13950
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
21.5%
2020 1 PoC

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVE-2020-22211
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-23982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'