2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-3250
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
89.7%
2020 CWE-20 2 PoCs

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-6137
OS4Ed Web Database
9.8
CRITICAL
EPSS
0.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-6141
OS4Ed Web Database
9.8
CRITICAL
EPSS
10.8%
2020 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-6756
Software Genérico Web
9.8
CRITICAL
EPSS
11.8%
2020 1 PoC

languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.

CVE-2020-8657
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.9%
2020 1 PoC

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

CVE-2020-3227
Cisco IOS XE Software 16.3.1 Web Networking
9.8
CRITICAL
EPSS
6.4%
2020 CWE-264 1 PoC

A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The vulnerability is due to incorrect handling of requests for authorization tokens. An attacker could exploit this vulnerability by using a crafted API call to request such a token. An exploit could allow the attacker to obtain an authorization token and execute any of the IOx API commands on an affected device.

CVE-2020-6138
OS4Ed Web Database
9.8
CRITICAL
EPSS
0.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The uname parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-36847
Simple File List Web Windows
9.8
CRITICAL
EPSS
89.3%
2020 CWE-434 2 PoCs

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVE-2020-12641
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.1%
2020 2 PoCs

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVE-2020-10826
Software Genérico Web
9.8
CRITICAL
EPSS
30.0%
2020 2 PoCs

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

CVE-2020-36849
AIT CSV import/export Web Windows
9.8
CRITICAL
EPSS
84.5%
2020 CWE-434 1 PoC

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for unauthorized attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2020-15429
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsing the user parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9716.

CVE-2020-2931
Knowledge Web Database
9.8
CRITICAL
EPSS
1.9%
2020 1 PoC

Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Web Applications - InfoCenter). Supported versions that are affected are 8.6.0-8.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks of this vulnerability can result in takeover of Oracle Knowledge. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-3243
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
90.2%
2020 CWE-20 2 PoCs

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-2950
Oracle Business Intelligence Enterprise Edition Web Database
9.8
CRITICAL
EPSS
85.9%
2020 2 PoCs

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CV

CVE-2020-2961
Enterprise Manager Base Platform Web Database
9.8
CRITICAL
EPSS
1.6%
2020 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (Oracle OHS)). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-10824
Software Genérico Web
9.8
CRITICAL
EPSS
5.5%
2020 2 PoCs

A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).

CVE-2020-3239
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
38.7%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-36084
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.

CVE-2020-36705
Adning Advertising Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
89.5%
2020 CWE-434 1 PoC

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.