2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-9758
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from unauthenticated to user-level access, leading to full account takeover. The attack fetches multiple credentials because they are stored in the database (stored XSS). This affects the mobile/chat URI via the lgn and psswrd parameters.

CVE-2020-24900
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

CVE-2020-17518
Apache Flink Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 CWE-23 3 PoCs

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVE-2020-19822
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

CVE-2020-23048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

CVE-2020-10452
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/save-article.php by adding a question mark (?) followed by the payload.

CVE-2020-8204
Pulse Connect Secure Web
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-79 1 PoC

A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.

CVE-2020-35774
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2020 0 PoCs

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

CVE-2020-15579
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).

CVE-2020-8116
dot-prop Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-471 2 PoCs

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

CVE-2020-23826
Software Genérico Web
N/A
UNKNOWN
EPSS
11.1%
2020 1 PoC

The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176

CVE-2020-10385
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

CVE-2020-9979
tvOS Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.

CVE-2020-10469
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-1934
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
27.2%
2020 1 PoC

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

CVE-2020-15906
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.0%
2020 2 PoCs

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVE-2020-29477
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

CVE-2020-25042
Software Genérico Web
N/A
UNKNOWN
EPSS
77.0%
2020 4 PoCs

An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.

CVE-2020-23973
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.

CVE-2020-35745
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.