2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-16208
N-Tron 702-W / 702M12-W Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-352 2 PoCs

The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).

CVE-2020-11441
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2020 0 PoCs

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVE-2020-9495
Apache Archiva Web Windows
N/A
UNKNOWN
EPSS
27.5%
2020 1 PoC

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

CVE-2020-28939
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

CVE-2020-35592
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.

CVE-2020-27196
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.

CVE-2020-11700
Software Genérico Web
N/A
UNKNOWN
EPSS
14.0%
2020 2 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

CVE-2020-0219
Android Web
N/A
UNKNOWN
EPSS
0.0%
2020 4 PoCs

In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081

CVE-2020-13943
Apache Tomcat Web
N/A
UNKNOWN
EPSS
9.6%
2020 2 PoCs

If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.

CVE-2020-7643
paypal-adaptive Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

CVE-2020-26938
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In oauth2-server (aka node-oauth2-server) through 3.1.1, the value of the redirect_uri parameter received during the authorization and token request is checked against an incorrect URI pattern ("[a-zA-Z][a-zA-Z0-9+.-]+:") before making a redirection. This allows a malicious client to pass an XSS payload through the redirect_uri parameter while making an authorization request. NOTE: this vulnerability is similar to CVE-2020-7741.

CVE-2020-28902
Software Genérico Web
N/A
UNKNOWN
EPSS
10.4%
2020 2 PoCs

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

CVE-2020-13693
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
41.3%
2020 1 PoC

An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

CVE-2020-7234
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen (after a successful login to the super account).

CVE-2020-13958
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal protocol may be called from the document event handler and other hyperlinks require a control-click.

CVE-2020-9455
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.

CVE-2020-26006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.

CVE-2020-8654
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

CVE-2020-35846
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 4 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

CVE-2020-19292
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.