2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-19625
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2020 0 PoCs

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

CVE-2020-35327
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

CVE-2020-10580
Software Genérico Web
N/A
UNKNOWN
EPSS
11.0%
2020 2 PoCs

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

CVE-2020-7651
snyk-broker Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.

CVE-2020-26766
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.

CVE-2020-10218
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

CVE-2020-13389
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/openSchedWifi schedStartTime and schedEndTime parameters for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-10478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.

CVE-2020-8839
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.

CVE-2020-10203
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Sonatype Nexus Repository before 3.21.2 allows XSS.

CVE-2020-11619
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 5 PoCs

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

CVE-2020-23697
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2020 0 PoCs

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

CVE-2020-36505
Delete All Comments Easily Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-352 3 PoCs

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

CVE-2020-29257
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.

CVE-2020-27385
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file> in the input field of the FileEditor. In FlexDotnetCMS before v1.5.8, it is also possible to access files by specifying the full path (e.g., C:\<file>). The files can then be edited via the FileEditor.

CVE-2020-20142
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.

CVE-2020-5515
Software Genérico Web Database
N/A
UNKNOWN
EPSS
62.4%
2020 2 PoCs

Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.

CVE-2020-2231
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVE-2020-18885
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2020 2 PoCs

Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.

CVE-2020-21142
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerabilty in IPFire 2.23 via the IPfire web UI in the mail.cgi.