2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-35396
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.

CVE-2020-5745
TCExam Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVE-2020-13865
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.

CVE-2020-15468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.

CVE-2020-25735
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.

CVE-2020-11556
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There are multiple persistent (stored) and reflected XSS vulnerabilities.