304 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-19295
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-24550
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2020 1 PoC

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

CVE-2020-10549
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-20627
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2020 0 PoCs

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

CVE-2020-11546
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 3 PoCs

SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

CVE-2020-5191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

CVE-2020-13945
Apache APISIX Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 4 PoCs

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

CVE-2020-6950
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
51.7%
2020 3 PoCs

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

CVE-2020-26153
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
13.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVE-2020-8115
https://github.com/revive-adserver/revive-adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2020 CWE-79 1 PoC

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printed back without proper escaping in a JavaScript context, allowing an attacker to execute arbitrary JS

CVE-2020-7209
LinuxKI General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2020 3 PoCs

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

CVE-2020-7107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2020-6171
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVE-2020-35846
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 4 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

CVE-2020-24912
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
31.9%
2020 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

CVE-2020-27191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.9%
2020 1 PoC

LionWiki before 3.2.12 allows an unauthenticated user to read files as the web server user via crafted string in the index.php f1 variable, aka Local File Inclusion. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2020-35713
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 3 PoCs

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

CVE-2020-8654
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

CVE-2020-8656
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
81.8%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.