2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-27366
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in wlscanresults.html in Humax HGB10R-02 BRGCAB version 1.0.03, allows local attackers to execute arbitrary code.

CVE-2020-8799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.

CVE-2020-28871
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 5 PoCs

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVE-2020-15693
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.

CVE-2020-24794
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.

CVE-2020-19778
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request.

CVE-2020-5413
Spring Integration Web
N/A
UNKNOWN
EPSS
2.2%
2020 CWE-502 4 PoCs

Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data contains malicious code for execution during deserialization. In order to protect against this type of attack, Kryo can be configured to require a set of trusted classes for (de)serialization. Spring Integration should be proactive against blocking unknown "deserialization gadgets" when configuring Kryo in code.

CVE-2020-28130
Software Genérico Web
N/A
UNKNOWN
EPSS
10.7%
2020 2 PoCs

An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

CVE-2020-35752
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVE-2020-23762
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.

CVE-2020-2230
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVE-2020-10435
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/my-languages.php by adding a question mark (?) followed by the payload.

CVE-2020-23974
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).

CVE-2020-9425
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.4%
2020 0 PoCs

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

CVE-2020-14962
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.

CVE-2020-35427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-5509
Software Genérico Web
N/A
UNKNOWN
EPSS
5.3%
2020 3 PoCs

PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.

CVE-2020-19159
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.

CVE-2020-27974
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.

CVE-2020-15003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).