3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-2140
Jenkins Audit Trail Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
44.8%
2020 0 PoCs

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

CVE-2020-5412
Spring Cloud Netflix Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 CWE-441 0 PoCs

Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.

CVE-2020-15718
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2020 2 PoCs

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.

CVE-2020-10547
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-16139
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
87.6%
2020 1 PoC

A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through sending specially crafted packets. Note: We cannot prove this vulnerability exists. Out of an abundance of caution, this CVE is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. For more information on this, and how to upgrade, refer to the CVE’s reference information

CVE-2020-23575
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.5%
2020 1 PoC

A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.

CVE-2020-27982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.9%
2020 2 PoCs

IceWarp 11.4.5.0 allows XSS via the language parameter.

CVE-2020-13886
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2020 4 PoCs

Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.

CVE-2020-15500
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.5%
2020 2 PoCs

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.

CVE-2020-23517
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

CVE-2020-29453
Jira Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.9%
2020 0 PoCs

The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

CVE-2020-17526
Apache Airflow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2020 0 PoCs

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

CVE-2020-14144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2020 3 PoCs

The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the ENABLE_GIT_HOOKS line in the config file). NOTE: The vendor has indicated this is not a vulnerability and states "This is a functionality of the software that is limited to a very limited subset of accounts. If you give someone the privilege to execute arbitrary code on your server, they can execute arbitrary code on your

CVE-2020-13851
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2020 3 PoCs

Artica Pandora FMS 7.44 allows remote command execution via the events feature.

CVE-2020-11530
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 2 PoCs

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

CVE-2020-8641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2020 1 PoC

Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.

CVE-2020-13820
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.1%
2020 2 PoCs

Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

CVE-2020-13640
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.9%
2020 3 PoCs

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)