2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-10879
Software Genérico Web
N/A
UNKNOWN
EPSS
86.2%
2020 1 PoC

rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.

CVE-2020-28871
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 5 PoCs

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVE-2020-12629
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

CVE-2020-29240
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.

CVE-2020-36493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-18664
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.

CVE-2020-24794
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.

CVE-2020-25735
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.

CVE-2020-15894
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.

CVE-2020-3678
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'A buffer overflow could occur if the API is improperly used due to UIE init does not contain a buffer size a param' in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Agatti, Kamorta, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SXR1130

CVE-2020-15537
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.

CVE-2020-19289
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.

CVE-2020-2140
Jenkins Audit Trail Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
44.8%
2020 0 PoCs

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

CVE-2020-25209
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

CVE-2020-24088
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.

CVE-2020-5412
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 CWE-441 0 PoCs

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

CVE-2020-9368
Software Genérico Web
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

The Module Olea Gift On Order module through 5.0.8 for PrestaShop enables an unauthenticated user to read arbitrary files on the server via getfile.php?file=/.. directory traversal.

CVE-2020-25273
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

CVE-2020-24860
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 3 PoCs

CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

CVE-2020-9402
Software Genérico Web Database
N/A
UNKNOWN
EPSS
85.5%
2020 1 PoC

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.