2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-14847
PeopleSoft Enterprise PT PeopleTools Web Database
2.7
LOW
EPSS
0.2%
2020 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVE-2020-36609
DuxCMS Web
2.4
LOW
EPSS
0.3%
2020 CWE-707 3 PoCs

A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215115.

CVE-2020-2769
Hyperion Financial Reporting Web Database
2.4
LOW
EPSS
0.4%
2020 1 PoC

Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Web Based Report Designer). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Reporting. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion Financial Reporting accessible data. CVSS 3.0 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVS

CVE-2020-1766
((OTRS)) Community Edition Web
2.0
LOW
EPSS
0.6%
2020 CWE-79 1 PoC

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVE-2020-14541
Hyperion Financial Close Management Web Database
2.0
LOW
EPSS
0.2%
2020 1 PoC

Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Close Management accessible data. CVSS 3.1 Base Score 2.0 (Integrity impact

CVE-2020-15600
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.

CVE-2020-13225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.

CVE-2020-20138
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.

CVE-2020-22165
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2020 0 PoCs

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-12800
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

CVE-2020-5393
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

CVE-2020-29045
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
35.2%
2020 1 PoC

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

CVE-2020-15918
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0.

CVE-2020-1902
WhatsApp for Android Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-200 1 PoC

A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.

CVE-2020-8142
https://github.com/revive-adserver/revive-adserver Web
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-863 1 PoC

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change the e-mail address or the password. It was however possible for anyone with access to a Revive Adserver admin user interface to bypass such check and change e-email address or password of the currently logged in user by altering the form payload.The attack requires physical access to the user interface of a logged in user. If the POST payload was

CVE-2020-23226
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

CVE-2020-10463
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVE-2020-13973
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.

CVE-2020-16171
Software Genérico Web
N/A
UNKNOWN
EPSS
11.2%
2020 1 PoC

An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.

CVE-2020-19291
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.