2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-36997
BacklinkSpeed General
9.8
CRITICAL
EPSS
0.0%
2020 CWE-121 2 PoCs

BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing arbitrary code and gaining control of the application.

CVE-2020-1747
PyYAML General
9.8
CRITICAL
EPSS
1.8%
2020 CWE-20 1 PoC

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.

CVE-2020-8515
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

CVE-2020-25506
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 1 PoC

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

CVE-2020-6067
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 2 PoCs

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFF tifread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted TIFF file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-7716
deeps General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package deeps are vulnerable to Prototype Pollution via the set function.

CVE-2020-7782
spritesheet-js General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.

CVE-2020-6068
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 2 PoCs

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-7701
madlib-object-utils General
9.8
CRITICAL
EPSS
1.1%
2020 2 PoCs

madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

CVE-2020-5847
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2020 3 PoCs

Unraid through 6.8.0 allows Remote Code Execution.

CVE-2020-7717
dot-notes General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

CVE-2020-28443
sonar-wrapper General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

CVE-2020-13561
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-6063
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-6065
Accusoft General
9.8
CRITICAL
EPSS
2.9%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-28447
xopen General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

CVE-2020-28423
monorepo-build General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package monorepo-build.

CVE-2020-7714
confucious General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package confucious are vulnerable to Prototype Pollution via the set function.

CVE-2020-6064
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.