2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10416
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/kb-backup.php by adding a question mark (?) followed by the payload.

CVE-2020-8286
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-295 4 PoCs

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CVE-2020-12432
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The WOPI API integration for Vereign Collabora CODE through 4.2.2 does not properly restrict delivery of JavaScript to a victim's browser, and lacks proper MIME type access control, which could lead to XSS that steals account credentials via cookies or local storage. The attacker must first obtain an API access token, which can be accomplished if the attacker is able to upload a .docx or .odt file. The associated API endpoints for exploitation are /wopi/files and /wopi/getAccessToken.

CVE-2020-7990
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Adive Framework 2.0.8 has admin/user/add userName XSS.

CVE-2020-13950
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
21.5%
2020 1 PoC

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

CVE-2020-22211
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-27385
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file> in the input field of the FileEditor. In FlexDotnetCMS before v1.5.8, it is also possible to access files by specifying the full path (e.g., C:\<file>). The files can then be edited via the FileEditor.

CVE-2020-23982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'

CVE-2020-13432
Software Genérico Web
N/A
UNKNOWN
EPSS
7.4%
2020 5 PoCs

rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.

CVE-2020-15046
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.

CVE-2020-29582
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 5 PoCs

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVE-2020-12629
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

CVE-2020-29240
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

CVE-2020-36493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-18664
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.

CVE-2020-15894
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.

CVE-2020-3678
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'A buffer overflow could occur if the API is improperly used due to UIE init does not contain a buffer size a param' in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Agatti, Kamorta, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SXR1130

CVE-2020-15537
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.

CVE-2020-19289
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.

CVE-2020-2140
Jenkins Audit Trail Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
44.8%
2020 0 PoCs

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.