2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-12648
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.

CVE-2020-13445
Software Genérico Web
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.

CVE-2020-9345
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.

CVE-2020-7107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2020-14943
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 4 PoCs

The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cross-site scripting (XSS) via Update User Profile.

CVE-2020-29287
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.5%
2020 2 PoCs

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

CVE-2020-24373
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

CVE-2020-7621
strong-nginx-controller Web
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.

CVE-2020-10437
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/optimize-database.php by adding a question mark (?) followed by the payload.

CVE-2020-13992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a crafted ticket.

CVE-2020-6578
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zen Cart 1.5.6d allows reflected XSS via the main_page parameter to includes/templates/template_default/common/tpl_main_page.php or includes/templates/responsive_classic/common/tpl_main_page.php.

CVE-2020-11989
Apache Shiro Web
N/A
UNKNOWN
EPSS
84.7%
2020 2 PoCs

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVE-2020-26110
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2020-27481
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.0%
2020 0 PoCs

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

CVE-2020-28957
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.

CVE-2020-15539
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.

CVE-2020-19295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-7904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

CVE-2020-10419
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-categories.php by adding a question mark (?) followed by the payload.