2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-29227
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 2 PoCs

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

CVE-2020-13174
- Management Console Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-1021 1 PoC

The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malicious link via clickjacking.

CVE-2020-22000
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user via the 'set_command_on' and 'set_command_off' POST parameters in '/system/systemplugins/customcommand/customcommand.plugin.php' by using an unsanitized PHP exec() function.

CVE-2020-8656
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
81.8%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

CVE-2020-25004
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-19147
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.

CVE-2020-15877
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'middleware' => ['can:admin']" in routes/web.php.

CVE-2020-11664
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.

CVE-2020-10457
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).

CVE-2020-13758
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.

CVE-2020-15895
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.7%
2020 1 PoC

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

CVE-2020-24723
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.

CVE-2020-36003
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

CVE-2020-15342
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.

CVE-2020-26510
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.

CVE-2020-9281
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2020 6 PoCs

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

CVE-2020-24664
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'pho:title' attribute of 'dashboardXml' parameter. Remediated in >= 7.1.0.25, >= 8.2.0.6, and >= 8.3.0.0 GA.

CVE-2020-12054
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2020 2 PoCs

The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

CVE-2020-3956
VMware Cloud Director Web Cloud
N/A
UNKNOWN
EPSS
41.2%
2020 3 PoCs

VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.