304 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-10973
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
24.8%
2020 0 PoCs

An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

CVE-2020-23575
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.5%
2020 1 PoC

A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.

CVE-2020-17506
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2020 3 PoCs

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

CVE-2020-27982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.9%
2020 2 PoCs

IceWarp 11.4.5.0 allows XSS via the language parameter.

CVE-2020-29214
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
45.3%
2020 1 PoC

SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

CVE-2020-24949
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.3%
2020 2 PoCs

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

CVE-2020-20988
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.

CVE-2020-13886
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2020 4 PoCs

Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.

CVE-2020-21224
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.1%
2020 2 PoCs

A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server

CVE-2020-15500
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.5%
2020 2 PoCs

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

CVE-2020-15920
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 4 PoCs

There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

CVE-2020-11710
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 1 PoC

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user de

CVE-2020-23517
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

CVE-2020-28188
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 3 PoCs

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVE-2020-29453
Jira Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2020 0 PoCs

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

CVE-2020-35729
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 4 PoCs

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

CVE-2020-35338
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.0%
2020 1 PoC

The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."

CVE-2020-17526
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2020 0 PoCs

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

CVE-2020-22165
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2020 0 PoCs

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.