2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-24604
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp

CVE-2020-12245
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

CVE-2020-10218
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

CVE-2020-35478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.

CVE-2020-7246
Software Genérico Web
N/A
UNKNOWN
EPSS
90.4%
2020 9 PoCs

A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of .htaccess protection. NOTE: this issue exists because of an incomplete fix for CVE-2015-3884.

CVE-2020-20285
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2020 0 PoCs

There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php

CVE-2020-5784
Teltonika Gateway TRB245 Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.

CVE-2020-13389
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and schedEndTime parameters for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-10416
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/kb-backup.php by adding a question mark (?) followed by the payload.

CVE-2020-8286
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-295 4 PoCs

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVE-2020-13950
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
21.5%
2020 1 PoC

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVE-2020-22211
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-23982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'

CVE-2020-13432
Software Genérico Web
N/A
UNKNOWN
EPSS
7.4%
2020 5 PoCs

rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.

CVE-2020-15046
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.

CVE-2020-29582
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 5 PoCs

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVE-2020-12629
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

CVE-2020-29240
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

CVE-2020-36493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-18664
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.