2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-6802
Mozilla Bleach Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.

CVE-2020-15716
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL.

CVE-2020-24949
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.3%
2020 2 PoCs

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

CVE-2020-24861
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

CVE-2020-28071
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.

CVE-2020-11436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

CVE-2020-15712
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path parameter to view arbitrary files on the system.

CVE-2020-8287
Node Web
N/A
UNKNOWN
EPSS
11.9%
2020 CWE-444 2 PoCs

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CVE-2020-35580
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.4%
2020 0 PoCs

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

CVE-2020-27387
Software Genérico Web
N/A
UNKNOWN
EPSS
70.3%
2020 3 PoCs

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

CVE-2020-13226
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

CVE-2020-5192
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

CVE-2020-5408
Spring Security Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-329 3 PoCs

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

CVE-2020-12625
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

CVE-2020-14209
Software Genérico Web
N/A
UNKNOWN
EPSS
10.2%
2020 2 PoCs

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).

CVE-2020-22987
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

CVE-2020-35136
Software Genérico Web
N/A
UNKNOWN
EPSS
7.0%
2020 2 PoCs

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

CVE-2020-22453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information.

CVE-2020-18657
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.

CVE-2020-35128
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.