304 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-22165
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2020 0 PoCs

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-14144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2020 3 PoCs

The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENABLE_GIT_HOOKS line in the config file). NOTE: The vendor has indicated this is not a vulnerability and states "This is a functionality of the software that is limited to a very limited subset of accounts. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your

CVE-2020-8497
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
22.4%
2020 0 PoCs

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

CVE-2020-13851
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Artica Pandora FMS 7.44 allows remote command execution via the events feature.

CVE-2020-5192
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

CVE-2020-27361
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 0 PoCs

An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.

CVE-2020-35580
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.4%
2020 0 PoCs

A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the contents of the SearchBlox configuration file (e.g., searchblox/WEB-INF/config.xml), which contains both the Super Admin's API key and the base64 encoded SHA1 password hashes of other SearchBlox users.

CVE-2020-11530
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 2 PoCs

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

CVE-2020-35476
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2020 3 PoCs

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

CVE-2020-9484
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2020 31 PoCs

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore t

CVE-2020-27467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2020 0 PoCs

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

CVE-2020-8641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2020 1 PoC

Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.

CVE-2020-13820
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.1%
2020 2 PoCs

Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

CVE-2020-13640
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.9%
2020 3 PoCs

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

CVE-2020-12262
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

CVE-2020-28185
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.6%
2020 2 PoCs

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

CVE-2020-13405
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2020 2 PoCs

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

CVE-2020-17505
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.6%
2020 2 PoCs

Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.