2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-7235
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).

CVE-2020-7995
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

CVE-2020-9463
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2020 1 PoC

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

CVE-2020-29053
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.

CVE-2020-10499
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

CVE-2020-10448
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php by adding a question mark (?) followed by the payload.

CVE-2020-10230
Software Genérico Web Database
N/A
UNKNOWN
EPSS
28.9%
2020 1 PoC

CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

CVE-2020-35717
Software Genérico Web
N/A
UNKNOWN
EPSS
6.1%
2020 4 PoCs

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

CVE-2020-35261
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.

CVE-2020-9375
Software Genérico Web
N/A
UNKNOWN
EPSS
28.0%
2020 4 PoCs

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.

CVE-2020-26669
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.

CVE-2020-16270
Software Genérico Web
N/A
UNKNOWN
EPSS
29.9%
2020 1 PoC

OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.

CVE-2020-10441
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-article-monthly.php by adding a question mark (?) followed by the payload.

CVE-2020-35664
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.

CVE-2020-8825
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.

CVE-2020-17453
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.7%
2020 3 PoCs

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

CVE-2020-13391
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetSpeedWan speed_dir parameter for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-8167
http://github.com/rails/rails Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-352 1 PoC

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

CVE-2020-12281
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

iSmartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to create a new user via /index.php.

CVE-2020-5502
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.