304 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-27615
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2020 3 PoCs

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

CVE-2020-8656
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
81.8%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-11547
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2020 1 PoC

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVE-2020-24912
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
31.9%
2020 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

CVE-2020-11930
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

CVE-2020-15895
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
13.7%
2020 1 PoC

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

CVE-2020-27191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2020 1 PoC

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2020-12800
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.

CVE-2020-5766
SRS Simple Hits Counter Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
39.1%
2020 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

CVE-2020-11975
Apache Unomi Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2020 0 PoCs

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

CVE-2020-13258
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2020 0 PoCs

Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.

CVE-2020-8654
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

CVE-2020-21998
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2020 1 PoC

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

CVE-2020-9315
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.

CVE-2020-24223
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2020 3 PoCs

Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.

CVE-2020-29390
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2020 0 PoCs

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

CVE-2020-29279
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.2%
2020 0 PoCs

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

CVE-2020-9376
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 1 PoC

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer