7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37149
EW-7438RPn Mini Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privileges.

CVE-2020-36993
LimeSurvey Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.

CVE-2020-37072
CMSsite Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

CVE-2020-36912
Plexus anblick Digital Signage Management General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-601 1 PoC

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter.

CVE-2020-36889
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.

CVE-2020-10722
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 3 PoCs

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.

CVE-2020-37046
Sistem Informasi Pengumuman Kelulusan Online Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the victim's consent.

CVE-2020-37106
Business Live Chat Software Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation endpoint with administrative access parameters.

CVE-2020-37014
Tryton Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 2 PoCs

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

CVE-2020-37145
HRSALE Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.

CVE-2020-37111
60CycleCMS Web Database
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection.

CVE-2020-37148
FNIP-8x16A Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser session in the context of the affected site. This can be exploited by submitting crafted input to the label modification functionality, such as the 'lab4' parameter in config.html.

CVE-2020-10724
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 2 PoCs

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

CVE-2020-37087
Easy Transfer Web
5.1
MEDIUM
EPSS
0.2%
2020 CWE-79 2 PoCs

Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts by manipulating the oldPath, newPath, and path parameters in Create Folder and Move/Edit functions. Attackers can exploit improper input validation via POST requests to execute arbitrary JavaScript in the context of the mobile web application.

CVE-2020-37022
OpenZ ERP Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 4 PoCs

OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.

CVE-2020-4788
VIOS General
5.1
MEDIUM
EPSS
0.2%
2020 1 PoC

IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.

CVE-2020-37118
FNIP-8x16A Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 2 PoCs

P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted page.

CVE-2020-36998
E-Learning Suite Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma.lms The E-Learning Suite 2.3.0.2 contains a persistent cross-site scripting vulnerability in multiple course and profile parameters. Attackers can inject malicious scripts in course code, name, description fields, and email parameter to execute arbitrary JavaScript without proper input sanitization.

CVE-2020-19248
Software Genérico Web Database
5.1
MEDIUM
EPSS
0.0%
2020 1 PoC

SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse templates.

CVE-2020-36954
Xeroneit Library Management System Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded.