14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-4854
Spectrum Protect Plus General
9.8
CRITICAL
EPSS
0.2%
2020 1 PoC

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 190454.

CVE-2020-28445
npm-help General
9.8
CRITICAL
EPSS
0.5%
2020 2 PoCs

This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

CVE-2020-10189
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2020 6 PoCs

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

CVE-2020-7784
ts-process-promises General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:

CVE-2020-6075
Accusoft General
9.8
CRITICAL
EPSS
1.4%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the store_data_buffer function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-26629
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2020 1 PoC

A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.

CVE-2020-7718
gammautils General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

CVE-2020-7720
node-forge General
9.8
CRITICAL
EPSS
2.1%
2020 4 PoCs

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

CVE-2020-23591
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2020 2 PoCs

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.

CVE-2020-5902
🔥 KEV BIG-IP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 63 PoCs

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

CVE-2020-11101
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2020 1 PoC

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

CVE-2020-7708
irrelon-path General
9.8
CRITICAL
EPSS
1.1%
2020 3 PoCs

The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

CVE-2020-28440
corenlp-js-interface General
9.8
CRITICAL
EPSS
4.1%
2020 1 PoC

All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

CVE-2020-7704
linux-cmdline General
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.

CVE-2016-9052
Aerospike version Aerospike Database Server 3.10.0.3 General
9.8
CRITICAL
EPSS
14.8%
2016 1 PoC

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_by_iname resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

CVE-2016-9053
Database Server General
9.8
CRITICAL
EPSS
5.4%
2016 2 PoCs

An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server to fetch a function table outside the bounds of an array resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

CVE-2016-9054
Database Server General
9.8
CRITICAL
EPSS
14.8%
2016 1 PoC

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_list_by_set_binid resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

CVE-2016-8705
Memcached General
9.8
CRITICAL
EPSS
12.6%
2016 1 PoC

Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

CVE-2016-9051
Database Server General
9.8
CRITICAL
EPSS
3.9%
2016 1 PoC

An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause an out-of-bounds write resulting in memory corruption which can lead to remote code execution. An attacker can simply connect to the port to trigger this vulnerability.

CVE-2016-20017
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
92.1%
2016 2 PoCs

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.