2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-29303
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote attackers to inject arbitrary web script or HTML via a POST to /wp-admin/admin.php?page=drts/directories&q=%2F with _drts_form_build_id parameter containing the XSS payload and _t_ parameter set to an invalid or non-existent CSRF token.

CVE-2020-19148
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.

CVE-2020-20989
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.

CVE-2020-15656
Firefox ESR Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVE-2020-12480
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.

CVE-2020-6637
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2020 1 PoC

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2020-6171
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVE-2020-25019
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

CVE-2020-10484
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.

CVE-2020-12882
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.

CVE-2020-13892
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The SportsPress plugin before 2.7.2 for WordPress allows XSS.

CVE-2020-25408
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.

CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2020-12259
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.3%
2020 0 PoCs

rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

CVE-2020-10935
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.

CVE-2020-27152
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.

CVE-2020-19151
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

CVE-2020-28139
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail field in offer.php.

CVE-2020-5770
Teltonika Gateway TRB245 Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVE-2020-8164
https://github.com/rails/rails Web
N/A
UNKNOWN
EPSS
7.4%
2020 CWE-502 1 PoC

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.