2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10723
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 3 PoCs

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

CVE-2020-36918
iDS6 DSSPro Digital Signage System Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft malicious web pages to trick logged-in administrators into adding unauthorized users by exploiting the lack of CSRF protections.

CVE-2020-36919
WPForms Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.

CVE-2020-36955
Grav CMS Admin Plugin Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.

CVE-2020-37019
Orchard Core Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

CVE-2020-36966
Dolibarr Web Windows
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.

CVE-2020-11293
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
5.1
MEDIUM
EPSS
0.0%
2020 1 PoC

Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-36993
LimeSurvey Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.

CVE-2020-37014
Tryton Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 2 PoCs

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

CVE-2020-37111
60CycleCMS Web Database
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection.

CVE-2020-36931
Click2Magic Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests.

CVE-2020-36940
Easy CD & DVD Cover Creator General
5.1
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.

CVE-2020-36891
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.

CVE-2020-37054
Navigate CMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.

CVE-2020-36978
Froxlor Froxlor Server Management Panel Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.

CVE-2020-37096
EW-7438RPn Mini Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.

CVE-2020-37144
Sysguard 6001 Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

CVE-2020-37091
Maian Support Helpdesk Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

CVE-2020-37152
PHP-Fusion Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.

CVE-2020-36960
Forma LMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.