2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-9029
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

CVE-2020-12835
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2020 4 PoCs

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

CVE-2020-10406
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-group.php by adding a question mark (?) followed by the payload.

CVE-2020-35249
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.

CVE-2020-28408
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.

CVE-2020-25761
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 4 PoCs

Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.

CVE-2020-26124
Software Genérico Web
N/A
UNKNOWN
EPSS
80.3%
2020 1 PoC

openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.

CVE-2020-18723
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipient side while forwarding an email to perform potentially malicious activities.

CVE-2020-7491
Tricon system versions 10.2.0 through 10.5.3 Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. This vulnerability was remediated in TCM version 10.5.4.

CVE-2020-13394
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetNetControlList list parameter for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-26163
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.

CVE-2020-20140
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.

CVE-2020-12669
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.

CVE-2020-23044
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-24198
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'

CVE-2020-29596
Software Genérico Web
N/A
UNKNOWN
EPSS
7.0%
2020 2 PoCs

MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.

CVE-2020-25444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.

CVE-2020-23839
Software Genérico Web
N/A
UNKNOWN
EPSS
16.9%
2020 4 PoCs

A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.

CVE-2020-10433
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-users.php by adding a question mark (?) followed by the payload.