2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-9488
Apache Log4j Web
N/A
UNKNOWN
EPSS
0.0%
2020 7 PoCs

Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

CVE-2020-10670
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.

CVE-2020-10421
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-departments.php by adding a question mark (?) followed by the payload.

CVE-2020-21652
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.

CVE-2020-35202
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.

CVE-2020-11698
Software Genérico Web
N/A
UNKNOWN
EPSS
84.2%
2020 3 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

CVE-2020-29551
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 3 PoCs

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php, _internal/pc/wake.php, _internal/error_u201409.txt, _internal/runcmd.php, _internal/getConfiguration.php, ews/autoload.php, ews/del.php, ews/mod.php, ews/sync.php, utils/backup/backup_server.php, utils/backup/restore_server.php, MyScreens/timeline.config, kreator.html5/test.php, and addedlogs.txt.

CVE-2020-28938
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.

CVE-2020-10501
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.

CVE-2020-29254
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 2 PoCs

TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to follow a maliciously crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user.

CVE-2020-36763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom parameters when adding or editing a post.

CVE-2020-11546
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 3 PoCs

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

CVE-2020-15536
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.

CVE-2020-18325
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

CVE-2020-29231
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.

CVE-2020-13416
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.

CVE-2020-10465
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVE-2020-26137
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVE-2020-14208
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.

CVE-2020-25267
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.