3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-17453
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.7%
2020 3 PoCs

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

CVE-2020-19625
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2020 0 PoCs

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

CVE-2020-28871
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 5 PoCs

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVE-2020-26879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.9%
2020 4 PoCs

Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

CVE-2020-10546
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-10220
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 4 PoCs

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

CVE-2020-11991
Apache Cocoon Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 0 PoCs

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

CVE-2020-9547
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
38.3%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

CVE-2020-8771
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 1 PoC

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

CVE-2020-7943
Puppet Enterprise 2018.1.x stream Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.4%
2020 CWE-276 1 PoC

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Ent

CVE-2020-27481
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.0%
2020 0 PoCs

An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.

CVE-2020-19295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-27735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
52.8%
2020 1 PoC

An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.

CVE-2020-26153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2020-13937
Apache Kylin Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 3 PoCs

Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 4.0.0-alpha has one restful api which exposed Kylin's configuration information without any authentication, so it is dangerous because some confidential information entries will be disclosed to everyone.

CVE-2020-5775
Instructure Canvas Learning Management System (LMS) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.8%
2020 1 PoC

Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.

CVE-2020-7209
LinuxKI General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 3 PoCs

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

CVE-2020-6637
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
69.5%
2020 1 PoC

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2020-6171
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.