3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-35476
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2020 3 PoCs

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

CVE-2020-19363
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.6%
2020 0 PoCs

Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.

CVE-2020-10548
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-35848
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 2 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

CVE-2020-11110
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.0%
2020 1 PoC

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVE-2020-12478
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.6%
2020 0 PoCs

TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

CVE-2020-26948
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2020 1 PoC

Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

CVE-2020-29164
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.2%
2020 0 PoCs

PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).

CVE-2020-17518
Apache Flink Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 CWE-23 3 PoCs

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.

CVE-2020-12116
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2020 1 PoC

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

CVE-2020-26876
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.4%
2020 0 PoCs

The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. This occurs because show_in_rest is enabled for custom post types (e.g., /wp-json/wp/v2/course and /wp-json/wp/v2/lesson exist).

CVE-2020-36510
15Zine Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.6%
2020 CWE-79 1 PoC

The 15Zine WordPress theme before 3.3.0 does not sanitise and escape the cbi parameter before outputing it back in the response via the cb_s_a AJAX action, leading to a Reflected Cross-Site Scripting

CVE-2020-8163
https://github.com/rails/rails Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2020 CWE-94 7 PoCs

The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2020-10770
keycloak General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 CWE-918 3 PoCs

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

CVE-2020-11450
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 1 PoC

Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.

CVE-2020-28976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.2%
2020 1 PoC

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

CVE-2020-8194
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2020 CWE-94 0 PoCs

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

CVE-2020-12124
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 2 PoCs

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

CVE-2020-9483
Apache SkyWalking Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 2 PoCs

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.