2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-25271
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.

CVE-2020-13933
Apache Shiro Web
N/A
UNKNOWN
EPSS
80.9%
2020 3 PoCs

Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.

CVE-2020-10540
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.

CVE-2020-13392
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/setcfm funcpara1 parameter for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-14973
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The loginForm within the general/login.php webpage in webTareas 2.0p8 suffers from a Reflected Cross Site Scripting (XSS) vulnerability via the query string.

CVE-2020-15919
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0.

CVE-2020-3984
VMware SD-WAN Orchestrator Web Database
N/A
UNKNOWN
EPSS
16.6%
2020 1 PoC

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.

CVE-2020-24912
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
31.9%
2020 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

CVE-2020-5786
Teltonika Gateway TRB245 Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVE-2020-13756
Software Genérico Web
N/A
UNKNOWN
EPSS
26.6%
2020 2 PoCs

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

CVE-2020-15538
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.

CVE-2020-10466
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVE-2020-27975
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

CVE-2020-25206
Software Genérico Web
N/A
UNKNOWN
EPSS
29.6%
2020 2 PoCs

The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the affected endpoints (/core/api/calls/Throughput.php, /core/api/calls/WANStats.php, /core/api/calls/PhyStats.php, /core/api/calls/QosStats.php). This results in the complete takeover of the vulnerable device. This vulnerability does not occur in the older 1.5.x firmware versions.

CVE-2020-12104
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.

CVE-2020-18717
Software Genérico Web Database
N/A
UNKNOWN
EPSS
7.2%
2020 1 PoC

SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

CVE-2020-21483
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.

CVE-2020-27515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.

CVE-2020-19914
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.

CVE-2020-9460
Software Genérico Web
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

Octech Oempro 4.7 through 4.11 allow XSS by an authenticated user. The parameter CampaignName in Campaign.Create is vulnerable.