2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-21991
Software Genérico Web
N/A
UNKNOWN
EPSS
5.3%
2020 2 PoCs

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

CVE-2020-19156
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.

CVE-2020-28039
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.0%
2020 1 PoC

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVE-2020-25986
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.

CVE-2020-36109
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
12.9%
2020 2 PoCs

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

CVE-2020-5748
TCExam Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-13625
Software Genérico Web
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

CVE-2020-21884
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.

CVE-2020-23148
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.

CVE-2020-9288
Fortinet FortiWLC Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.

CVE-2020-12841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php

CVE-2020-24709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.

CVE-2020-10393
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-field.php by adding a question mark (?) followed by the payload.

CVE-2020-6845
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin accounts can be taken over in a DOM-Based XSS attack.

CVE-2020-22841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

CVE-2020-28904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

CVE-2020-11971
Apache Camel Web
N/A
UNKNOWN
EPSS
9.7%
2020 3 PoCs

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.

CVE-2020-8778
Software Genérico Web
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.

CVE-2020-12137
Software Genérico Web
N/A
UNKNOWN
EPSS
5.2%
2020 1 PoC

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.