14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-12504
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.6%
2020 CWE-912 5 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-7796
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2020 0 PoCs

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

CVE-2020-7721
node-oojs General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

CVE-2020-28446
ntesseract General
9.8
CRITICAL
EPSS
11.6%
2020 1 PoC

The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

CVE-2020-13109
Software Genérico General
9.8
CRITICAL
EPSS
2.7%
2020 1 PoC

Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to top-level command 7) has a stack-based buffer overflow.

CVE-2020-7727
gedi General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package gedi are vulnerable to Prototype Pollution via the set function.

CVE-2020-12501
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.9%
2020 CWE-798 6 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

CVE-2020-13585
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the PSD Header processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-13571
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the SGI RLE decompression functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-37010
BearShare Lite General
9.8
CRITICAL
EPSS
0.1%
2020 CWE-120 2 PoCs

BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywords field.

CVE-2020-3952
🔥 KEV VMware vCenter Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

CVE-2020-13556
EIP Stack Group General
9.8
CRITICAL
EPSS
2.6%
2020 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2020-6082
Accusoft General
9.8
CRITICAL
EPSS
1.4%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the ico_read function of the igcore19d.dll library of Accusoft ImageGear 19.6.0. A specially crafted ICO file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-7247
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.1%
2020 16 PoCs

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

CVE-2020-4450
WebSphere Application Server General
9.8
CRITICAL
EPSS
71.9%
2020 1 PoC

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.

CVE-2020-7785
node-ps General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.

CVE-2020-0646
🔥 KEV Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 General
9.8
CRITICAL
EPSS
93.9%
2020 1 PoC

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVE-2020-7706
connie-lang General
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

CVE-2020-11307
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.4%
2020 1 PoC

Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables