2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-14413
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2020 0 PoCs

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

CVE-2020-12816
Fortinet FortiNAC Web Networking
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.

CVE-2020-24963
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

CVE-2020-22719
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.

CVE-2020-15308
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

CVE-2020-36012
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVE-2020-35328
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Courier Management System 1.0 - 'First Name' Stored XSS

CVE-2020-10985
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php.

CVE-2020-11973
Apache Camel Web
N/A
UNKNOWN
EPSS
14.1%
2020 5 PoCs

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-8184
https://github.com/rack/rack Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-784 3 PoCs

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

CVE-2020-10963
Software Genérico Web
N/A
UNKNOWN
EPSS
22.4%
2020 2 PoCs

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

CVE-2020-25659
python-cryptography Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-385 2 PoCs

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

CVE-2020-22428
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.

CVE-2020-12832
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2020 0 PoCs

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVE-2020-6843
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 3 PoCs

Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.

CVE-2020-18114
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

CVE-2020-13413
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.

CVE-2020-25454
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.