2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-13444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

CVE-2020-25068
Software Genérico Web
N/A
UNKNOWN
EPSS
15.2%
2020 2 PoCs

Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.

CVE-2020-11455
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 2 PoCs

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

CVE-2020-25006
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-13890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.

CVE-2020-7989
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Adive Framework 2.0.8 has admin/user/add userUsername XSS.

CVE-2020-8637
Software Genérico Web Database
N/A
UNKNOWN
EPSS
11.2%
2020 1 PoC

A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

CVE-2020-16257
Software Genérico Web
N/A
UNKNOWN
EPSS
6.3%
2020 1 PoC

Winston 1.5.4 devices are vulnerable to command injection via the API.

CVE-2020-16608
Software Genérico Web
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

CVE-2020-35418
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.

CVE-2020-20444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

CVE-2020-10467
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/edit-comment.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVE-2020-24701
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.9%
2020 3 PoCs

OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

CVE-2020-35660
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.

CVE-2020-25786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

CVE-2020-6586
Software Genérico Web
N/A
UNKNOWN
EPSS
7.3%
2020 1 PoC

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.

CVE-2020-23046
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.

CVE-2020-19275
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.

CVE-2020-28092
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=

CVE-2020-9036
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.2%
2020 1 PoC

Jeedom through 4.0.38 allows XSS.