7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-29304
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

CVE-2020-15928
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.

CVE-2020-15855
bodhi Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

CVE-2020-9021
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.

CVE-2020-28657
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.

CVE-2020-8290
Backblaze Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-269 3 PoCs

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

CVE-2020-10487
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.

CVE-2020-26108
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

CVE-2020-27617
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.

CVE-2020-10405
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-glossary.php by adding a question mark (?) followed by the payload.

CVE-2020-23836
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.

CVE-2020-26516
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.

CVE-2020-14025
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as installing new modules or changing a password.

CVE-2020-6794
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

CVE-2020-15390
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.

CVE-2020-25557
Software Genérico Web
N/A
UNKNOWN
EPSS
6.3%
2020 2 PoCs

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

CVE-2020-16024
Chrome General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-13650
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.

CVE-2020-12134
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.