2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-13946
Apache Cassandra Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

CVE-2020-8461
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.

CVE-2020-6640
Fortinet FortiAnalyzer Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.

CVE-2020-6615
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

CVE-2020-10411
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/email-harvester.php by adding a question mark (?) followed by the payload.

CVE-2020-22840
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
42.7%
2020 2 PoCs

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

CVE-2020-29443
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

CVE-2020-28038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

WordPress before 5.5.2 allows stored XSS via post slugs.

CVE-2020-12393
Firefox ESR Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

CVE-2020-7050
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.

CVE-2020-23376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.

CVE-2020-11749
Software Genérico Web
N/A
UNKNOWN
EPSS
5.8%
2020 4 PoCs

Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.

CVE-2020-14043
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to download a plugin from the marketplace is only available to admin users and it isn't CSRF protected in components/market/controller.php. This might cause admins to make a vulnerable request without them knowing and result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."

CVE-2020-1915
Hermes Web
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-125 1 PoC

An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.

CVE-2020-35271
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.

CVE-2020-36499
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content parameter of the Rubric Block (Add) module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the rubric name value.

CVE-2020-18326
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

CVE-2020-3680
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MSM8909W, MSM8917, MSM8953, QCS605, QM215, SA415M, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SXR1130

CVE-2020-11457
Software Genérico Web
N/A
UNKNOWN
EPSS
5.9%
2020 2 PoCs

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

CVE-2020-23761
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.