7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10068
zephyr General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-20 1 PoC

In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resulting in a denial of service. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.

CVE-2020-36932
Seacms Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.

CVE-2020-10723
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 3 PoCs

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

CVE-2020-37003
Sellacious eCommerce Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 2 PoCs

Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user sessions and manipulate application modules.

CVE-2020-37103
DotNetNuke Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.

CVE-2020-37026
Sickbeard Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configuration parameters. Attackers can trick users into submitting a malicious form that clears web username and password, effectively removing authentication protection.

CVE-2020-37072
CMSsite Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

CVE-2020-10724
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 2 PoCs

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

CVE-2020-36905
Home Center 3 Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-829 2 PoCs

FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.

CVE-2020-37018
GOautodial Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.

CVE-2020-36996
PHPFusion Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.

CVE-2020-36960
Forma LMS Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

CVE-2020-36955
Grav CMS Admin Plugin Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.

CVE-2020-37152
PHP-Fusion Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the 'panel_content' field in panels.php, resulting in execution of malicious scripts in the context of the affected site.

CVE-2020-37091
Maian Support Helpdesk Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

CVE-2020-37144
Sysguard 6001 Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent.

CVE-2020-37019
Orchard Core Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

CVE-2020-36966
Dolibarr Web Windows
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.

CVE-2020-36908
SnapGear Management Console SG560 Web
5.1
MEDIUM
EPSS
0.1%
2020 CWE-352 2 PoCs

SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative privileges when a logged-in user visits the page.

CVE-2020-37096
EW-7438RPn Mini Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.