2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-24862
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

CVE-2020-15599
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

CVE-2020-16157
Software Genérico Web
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.

CVE-2020-22984
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

CVE-2020-11659
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to perform a restricted user administration action.

CVE-2020-35416
Software Genérico Web
N/A
UNKNOWN
EPSS
4.5%
2020 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

CVE-2020-11660
CA API Developer Portal Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.

CVE-2020-10430
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-subscribers.php by adding a question mark (?) followed by the payload.

CVE-2020-15689
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.

CVE-2020-10498
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.

CVE-2020-35223
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The CSRF protection mechanism implemented in the web administration panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices could be bypassed by omitting the CSRF token parameter in HTTP requests.

CVE-2020-11456
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).

CVE-2020-25399
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

CVE-2020-15873
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.

CVE-2020-27976
Software Genérico Web
N/A
UNKNOWN
EPSS
21.5%
2020 2 PoCs

osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.

CVE-2020-11100
Software Genérico Web
N/A
UNKNOWN
EPSS
74.8%
2020 2 PoCs

In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.

CVE-2020-13945
Apache APISIX Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 4 PoCs

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

CVE-2020-10436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/my-profile.php by adding a question mark (?) followed by the payload.

CVE-2020-12261
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Open-AudIT 3.3.0 allows an XSS attack after login.

CVE-2020-20139
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.