2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-36490
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-5746
TCExam Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.

CVE-2020-9335
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-35228
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.

CVE-2020-10497
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.

CVE-2020-8803
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

CVE-2020-13700
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2020 0 PoCs

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.

CVE-2020-13156
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

CVE-2020-12255
Software Genérico Web
N/A
UNKNOWN
EPSS
58.6%
2020 1 PoC

rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header. Thus, an attacker can exploit this by uploading a .php file to vendor.php that contains arbitrary PHP code and changing the content-type to image/gif.

CVE-2020-15713
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2020-10447
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-failed-login.php by adding a question mark (?) followed by the payload.

CVE-2020-11803
Software Genérico Web
N/A
UNKNOWN
EPSS
8.7%
2020 2 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.

CVE-2020-28351
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
25.7%
2020 2 PoCs

The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.

CVE-2020-25627
Moodle Web
N/A
UNKNOWN
EPSS
5.4%
2020 CWE-79 2 PoCs

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVE-2020-24708
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.

CVE-2020-18116
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.

CVE-2020-10111
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

CVE-2020-26153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2020-28005
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial of service) by sending a POST request to the /admin/syslog endpoint. Fixed version: TL-WPA4220(EU)_V4_201023

CVE-2020-16210
N-Tron 702-W / 702M12-W Web
N/A
UNKNOWN
EPSS
1.5%
2020 CWE-79 3 PoCs

The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).