3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-28185
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.6%
2020 2 PoCs

User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

CVE-2020-13405
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
53.3%
2020 2 PoCs

userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.

CVE-2020-22208
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
32.2%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2020-25864
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.3%
2020 1 PoC

HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.

CVE-2020-1943
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2020 0 PoCs

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

CVE-2020-12256
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.9%
2020 0 PoCs

rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

CVE-2020-9484
Apache Tomcat Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2020 31 PoCs

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore t

CVE-2020-24571
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 0 PoCs

NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal.

CVE-2020-29395
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.

CVE-2020-13167
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 0 PoCs

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

CVE-2020-24285
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
13.1%
2020 0 PoCs

INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx.

CVE-2020-8982
Software Genérico Networking Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.9%
2020 1 PoC

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are internet facing). NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability

CVE-2020-8209
Citrix XenMobile Server Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 CWE-22 1 PoC

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

CVE-2020-15050
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.0%
2020 1 PoC

An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.

CVE-2020-11529
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
70.3%
2020 0 PoCs

Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

CVE-2020-24148
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2020 1 PoC

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

CVE-2020-35234
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
81.5%
2020 0 PoCs

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.

CVE-2020-13942
Apache Unomi Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 CWE-20 7 PoCs

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.