3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2020-12259
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.3%
2020 0 PoCs

rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

CVE-2020-8191
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.0%
2020 CWE-79 0 PoCs

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

CVE-2020-35847
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

CVE-2020-19360
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2020 2 PoCs

Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.

CVE-2020-28653
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 4 PoCs

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

CVE-2020-19282
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

CVE-2020-27615
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.3%
2020 3 PoCs

The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.

CVE-2020-13258
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2020 0 PoCs

Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-11547
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2020 1 PoC

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVE-2020-24881
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2020 3 PoCs

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

CVE-2020-20601
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
57.7%
2020 0 PoCs

An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

CVE-2020-12447
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2020 0 PoCs

A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.

CVE-2020-5777
MAGMI Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
89.7%
2020 1 PoC

MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.

CVE-2020-19283
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-29047
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.6%
2020 1 PoC

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

CVE-2020-35131
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2020 1 PoC

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

CVE-2020-20285
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2020 0 PoCs

There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php

CVE-2020-22211
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.