2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-8191
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2020 CWE-79 0 PoCs

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

CVE-2020-25453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

CVE-2020-23984
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.

CVE-2020-35395
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

CVE-2020-23151
Software Genérico Web
N/A
UNKNOWN
EPSS
55.6%
2020 1 PoC

rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.

CVE-2020-13433
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

CVE-2020-26583
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is required. By exploiting this vulnerability, an attacker can persistently include arbitrary HTML or JavaScript code into the affected web page. The vulnerability can be used to change the contents of the displayed site, redirect to other sites, or steal user credentials. Additionally, users are potential victims of browser exploits and JavaScript malware.

CVE-2020-24219
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
25.2%
2020 1 PoC

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

CVE-2020-5903
BIG-IP Web
N/A
UNKNOWN
EPSS
9.1%
2020 2 PoCs

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

CVE-2020-13259
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 3 PoCs

A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE

CVE-2020-6850
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.

CVE-2020-25487
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

CVE-2020-27358
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 2 PoCs

An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request to the endpoint Messenger/messenger_download_csv.php?title=Hey&thread_id={THREAD_ID}.

CVE-2020-27509
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs into their mailbox.

CVE-2020-7593
LOGO! 8 BM (incl. SIPLUS variants) Web
N/A
UNKNOWN
EPSS
17.3%
2020 CWE-120 1 PoC

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerability exists in the Web Server functionality of the device. A remote unauthenticated attacker could send a specially crafted HTTP request to cause a memory corruption, potentially resulting in remote code execution.

CVE-2020-15020
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.

CVE-2020-29238
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
49.6%
2020 1 PoC

An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensitive information when the server running as reverse proxy via specially crafted request.

CVE-2020-35847
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2020-8465
Trend Micro InterScan Web Security Virtual Appliance Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.