2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-12262
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

CVE-2020-12429
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.

CVE-2020-22158
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

CVE-2020-7988
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

CVE-2020-7934
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 5 PoCs

In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.

CVE-2020-8162
https://github.com/rails/rails Web Cloud
N/A
UNKNOWN
EPSS
1.5%
2020 CWE-602 1 PoC

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVE-2020-27666
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

CVE-2020-28722
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.

CVE-2020-29364
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.

CVE-2020-35124
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

CVE-2020-15896
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2020 1 PoC

An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of checking the value of NO_NEED_AUTH. If the value of NO_NEED_AUTH is 1, the user has direct access to the webpage without any authentication. By appending a query string NO_NEED_AUTH with the value of 1 to any protected URL, any unauthorized user can access the application directly, as demonstrated by bsc_lan.php?NO_NEED_AUTH=1.

CVE-2020-23978
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

CVE-2020-28870
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.

CVE-2020-18875
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.

CVE-2020-29458
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

CVE-2020-11439
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.

CVE-2020-35729
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 4 PoCs

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

CVE-2020-8819
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

CVE-2020-17523
Apache Shiro Web
N/A
UNKNOWN
EPSS
88.8%
2020 1 PoC

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVE-2020-5195
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path modification must be done on a publicly shared folder for a remote attacker to insert arbitrary JavaScript or HTML. The vulnerability impacts anyone who clicks the malicious link crafted by the attacker.