2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-15363
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
14.2%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

CVE-2020-11583
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.

CVE-2020-12743
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a hidden_req POST parameter.

CVE-2020-20746
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.

CVE-2020-10410
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-user.php by adding a question mark (?) followed by the payload.

CVE-2020-24609
Software Genérico Web
N/A
UNKNOWN
EPSS
18.2%
2020 3 PoCs

TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via crafted payload.

CVE-2020-25952
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-15038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.

CVE-2020-27821
QEMU Web
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.

CVE-2020-36238
Jira Server Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-863 1 PoC

The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check.

CVE-2020-2096
Jenkins Gitlab Hook Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2020 1 PoC

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

CVE-2020-9466
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.

CVE-2020-10387
Software Genérico Web
N/A
UNKNOWN
EPSS
12.8%
2020 4 PoCs

Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

CVE-2020-14024
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuration, or (4) any GET Parameter in the /default URL of the application.

CVE-2020-5791
Nagios XI Web
N/A
UNKNOWN
EPSS
87.8%
2020 4 PoCs

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVE-2020-10402
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-category.php by adding a question mark (?) followed by the payload.

CVE-2020-35437
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

CVE-2020-10248
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BWA DiREX-Pro 1.2181 devices allow remote attackers to discover passwords via a direct request to val_users.php3.

CVE-2020-10109
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 2 PoCs

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.