304 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-15081
PrestaShop Web ⚡ nuclei
5.3
MEDIUM
EPSS
9.7%
2020 CWE-548 0 PoCs

In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.

CVE-2020-36723
ListingPro - WordPress Directory & Listing Theme Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
20.7%
2020 CWE-200 0 PoCs

The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone numbers, physical addresses and user post counts.

CVE-2020-36289
Jira Server General ⚡ nuclei
5.3
MEDIUM
EPSS
92.0%
2020 0 PoCs

Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1.

CVE-2020-24902
Software Genérico Web ⚡ nuclei
4.7
MEDIUM
EPSS
6.8%
2020 1 PoC

Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVE-2020-7318
ePolicy Orchistrator (ePO) Web ⚡ nuclei
4.6
MEDIUM
EPSS
12.5%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

CVE-2020-5284
next.js General ⚡ nuclei
4.4
MEDIUM
EPSS
83.2%
2020 CWE-23 0 PoCs

Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

CVE-2020-26836
SAP Solution Manager (Trace Analysis) General ⚡ nuclei
3.4
LOW
EPSS
8.7%
2020 1 PoC

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.

CVE-2020-35736
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.4%
2020 0 PoCs

GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

CVE-2020-35774
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2020 0 PoCs

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

CVE-2020-25495
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.

CVE-2020-15906
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.0%
2020 2 PoCs

tiki-login.php in Tiki before 21.2 sets the admin password to a blank value after 50 invalid login attempts.

CVE-2020-11455
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 2 PoCs

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

CVE-2020-9036
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.2%
2020 1 PoC

Jeedom through 4.0.38 allows XSS.

CVE-2020-24701
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.9%
2020 3 PoCs

OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

CVE-2020-11515
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2020 0 PoCs

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).

CVE-2020-23697
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2020 0 PoCs

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

CVE-2020-13121
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 0 PoCs

Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

CVE-2020-14413
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2020 0 PoCs

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVE-2020-12832
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2020 0 PoCs

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.