49 vulnerabilidades · General · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2020-6207
🔥 KEV SAP Solution Manager (User Experience Monitoring) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.2%
2020 6 PoCs

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

CVE-2020-2021
🔥 KEV PAN-OS General
10.0
CRITICAL
EPSS
19.0%
2020 CWE-347 1 PoC

When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This i

CVE-2020-6287
🔥 KEV SAP NetWeaver AS JAVA (LM Configuration Wizard) General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2020 8 PoCs

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

CVE-2020-15415
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2020 0 PoCs

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CVE-2020-7796
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2020 0 PoCs

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

CVE-2020-7247
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.1%
2020 16 PoCs

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

CVE-2020-5847
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2020 3 PoCs

Unraid through 6.8.0 allows Remote Code Execution.

CVE-2020-8515
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

CVE-2020-25506
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 1 PoC

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

CVE-2020-0646
🔥 KEV Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 General
9.8
CRITICAL
EPSS
93.9%
2020 1 PoC

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVE-2020-15505
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 2 PoCs

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2020-3992
🔥 KEV VMware ESXi General
9.8
CRITICAL
EPSS
90.9%
2020 1 PoC

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CVE-2020-8644
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2020 3 PoCs

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

CVE-2020-11651
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.2%
2020 14 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVE-2020-26919
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2020 1 PoC

NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

CVE-2020-10189
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2020 6 PoCs

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

CVE-2020-10987
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2020 1 PoC

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVE-2020-3952
🔥 KEV VMware vCenter Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.