2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-9520
Micro Focus Vibe. Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.

CVE-2020-35852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.

CVE-2020-35126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.

CVE-2020-36503
Connections Business Directory Web Windows
N/A
UNKNOWN
EPSS
1.3%
2020 CWE-1236 1 PoC

The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

CVE-2020-29164
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2020 0 PoCs

PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).

CVE-2020-8462
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.

CVE-2020-7660
serialize-javascript Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

CVE-2020-10470
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-23983
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.

CVE-2020-10413
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/import-html.php by adding a question mark (?) followed by the payload.

CVE-2020-13934
Apache Tomcat Web
N/A
UNKNOWN
EPSS
23.4%
2020 6 PoCs

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

CVE-2020-7910
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.

CVE-2020-10983
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.

CVE-2020-19305
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.

CVE-2020-14320
Moodle Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-79 1 PoC

In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

CVE-2020-17462
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.

CVE-2020-11883
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2020 1 PoC

In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.

CVE-2020-18648
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".

CVE-2020-29215
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.