2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-5530
Easy Property Listings Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2020-1913
Hermes Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-195 1 PoC

An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVE-2020-27016
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a cross-site request forgery (CSRF) vulnerability which could allow an attacker to modify policy rules by tricking an authenticated administrator into accessing an attacker-controlled web page. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

CVE-2020-17505
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2020 2 PoCs

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

CVE-2020-27467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2020 0 PoCs

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

CVE-2020-12666
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

CVE-2020-25889
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2020 4 PoCs

Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.

CVE-2020-5505
Software Genérico Web
N/A
UNKNOWN
EPSS
22.9%
2020 1 PoC

Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.

CVE-2020-8161
https://github.com/rack/rack Web
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-548 2 PoCs

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

CVE-2020-28927
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

CVE-2020-27388
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

CVE-2020-23837
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.

CVE-2020-10427
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-languages.php by adding a question mark (?) followed by the payload.

CVE-2020-8263
Pulse Connect Secure / Pulse Policy Secure Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-79 1 PoC

A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.

CVE-2020-36011
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

CVE-2020-14294
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 4 PoCs

An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.

CVE-2020-5750
TCExam Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-36112
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.5%
2020 1 PoC

CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.

CVE-2020-5781
IgniteNet HeliOS GLinq Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary javascript, this causes a denial-of-service condition for all other users.

CVE-2020-7913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.