7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-22987
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

CVE-2020-24381
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.

CVE-2020-10396
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-language.php by adding a question mark (?) followed by the payload.

CVE-2020-35593
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

CVE-2020-27461
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2020 1 PoC

A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.

CVE-2020-35124
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.

CVE-2020-16147
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.

CVE-2020-36476
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

CVE-2020-22453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Untis WebUntis before 2020.9.6 allows XSS in multiple functions that store information.

CVE-2020-23978
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

CVE-2020-12262
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

CVE-2020-18657
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.

CVE-2020-12713
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.

CVE-2020-17523
Apache Shiro Web
N/A
UNKNOWN
EPSS
88.8%
2020 1 PoC

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVE-2020-22158
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

CVE-2020-29654
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

CVE-2020-8819
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

CVE-2020-5530
Easy Property Listings Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2020-25967
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.

CVE-2020-15719
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.