2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-24948
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
23.4%
2020 2 PoCs

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

CVE-2020-5810
Umbraco CMS Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload.

CVE-2020-10407
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-news.php by adding a question mark (?) followed by the payload.

CVE-2020-27182
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in konzept-ix publiXone before 2020.015 allow remote attackers to inject arbitrary JavaScript or HTML via appletError.jsp, job_jacket_detail.jsp, ixedit/editor_component.jsp, or the login form.

CVE-2020-36553
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.

CVE-2020-27574
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site request forgery (CSRF). If an authenticated user visits a malicious page, unintended actions could be performed in the web application as the authenticated user.

CVE-2020-22210
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
43.9%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-27735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
52.8%
2020 1 PoC

An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.

CVE-2020-8596
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).

CVE-2020-28901
Software Genérico Web
N/A
UNKNOWN
EPSS
5.5%
2020 2 PoCs

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

CVE-2020-7249
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account).

CVE-2020-10486
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.

CVE-2020-19643
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page.

CVE-2020-28146
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

CVE-2020-25272
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.

CVE-2020-28926
Software Genérico Web
N/A
UNKNOWN
EPSS
66.1%
2020 2 PoCs

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.

CVE-2020-9472
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

CVE-2020-10450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-traffic.php by adding a question mark (?) followed by the payload.

CVE-2020-13828
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.