2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-23976
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.

CVE-2020-13393
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/saveParentControlInfo deviceId and time parameters for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-15855
bodhi Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

CVE-2020-27160
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
4.9%
2020 2 PoCs

Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

CVE-2020-15568
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 2 PoCs

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

CVE-2020-26061
Software Genérico Web
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.

CVE-2020-28187
Software Genérico Web
N/A
UNKNOWN
EPSS
64.2%
2020 2 PoCs

Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.

CVE-2020-10546
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-10220
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 4 PoCs

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

CVE-2020-26516
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.

CVE-2020-11991
Apache Cocoon Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 0 PoCs

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

CVE-2020-26527
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.

CVE-2020-5738
Grandstream GXP1600 Series Web Networking
N/A
UNKNOWN
EPSS
5.1%
2020 CWE-59 1 PoC

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.

CVE-2020-9459
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings.

CVE-2020-8168
AirMax AirOS for TI, XW and XM boards Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-352 3 PoCs

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against cross-site request forgery (CSRF), as a result authenticated users can be persuaded to visit malicious web pages, which allows attackers to perform arbitrary actions, such as downgrade the device's firmware to older versions, modify configuration, upload arbitrary firmware, exfiltrate files and tokens.Mitigation:Update

CVE-2020-22198
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

CVE-2020-8771
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 1 PoC

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

CVE-2020-7943
Puppet Enterprise 2018.1.x stream Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.4%
2020 CWE-276 1 PoC

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Ent

CVE-2020-22937
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.

CVE-2020-10401
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-article.php by adding a question mark (?) followed by the payload.