2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-8947
Software Genérico Web
N/A
UNKNOWN
EPSS
17.5%
2020 1 PoC

functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.

CVE-2020-22249
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2020 1 PoC

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution

CVE-2020-5844
Software Genérico Web
N/A
UNKNOWN
EPSS
73.8%
2020 5 PoCs

index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

CVE-2020-11811
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this malicious file.

CVE-2020-29241
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.

CVE-2020-12113
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

CVE-2020-10446
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-category.php by adding a question mark (?) followed by the payload.

CVE-2020-28072
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2020 1 PoC

A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

CVE-2020-20907
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.

CVE-2020-10420
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php by adding a question mark (?) followed by the payload.

CVE-2020-6844
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.

CVE-2020-20627
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2020 0 PoCs

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

CVE-2020-10456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/trash-box.php by adding a question mark (?) followed by the payload.

CVE-2020-19285
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

CVE-2020-10464
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.

CVE-2020-24217
Software Genérico Web
N/A
UNKNOWN
EPSS
31.9%
2020 2 PoCs

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

CVE-2020-18659
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php

CVE-2020-7606
docker-compose-remote-api DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.

CVE-2020-19154
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

CVE-2020-9000
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exhausted, therefore consuming the maximum amount of resources (triggering a denial of service condition).