2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-11553
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.

CVE-2020-23049
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-9019
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.

CVE-2020-20300
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
56.1%
2020 0 PoCs

SQL injection vulnerability in the wp_where function in WeiPHP 5.0.

CVE-2020-26102
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

CVE-2020-12840
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

CVE-2020-29304
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

CVE-2020-23972
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
73.2%
2020 2 PoCs

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

CVE-2020-6585
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Nagios Log Server 2.1.3 has CSRF.

CVE-2020-10487
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.

CVE-2020-10405
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-glossary.php by adding a question mark (?) followed by the payload.

CVE-2020-11972
Apache Camel Web
N/A
UNKNOWN
EPSS
6.9%
2020 2 PoCs

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-23836
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.

CVE-2020-27219
Eclipse Hawkbit Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-79 1 PoC

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST request to a non existing resource will return the full path from the given URL unescaped to the client.

CVE-2020-36389
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

In CiviCRM before 5.28.1 and CiviCRM ESR before 5.27.5 ESR, the CKEditor configuration form allows CSRF.

CVE-2020-10403
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-comment.php by adding a question mark (?) followed by the payload.

CVE-2020-14025
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.

CVE-2020-15053
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
11.8%
2020 1 PoC

An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.

CVE-2020-10549
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-10239
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.