3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-12961
2nd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-20 1 PoC

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.

CVE-2020-14179
Jira Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2020 4 PoCs

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVE-2020-21994
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 3 PoCs

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

CVE-2020-0380
Android General
N/A
UNKNOWN
EPSS
5.6%
2020 1 PoC

In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979

CVE-2020-5774
Tenable Nessus General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser session.

CVE-2020-26886
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data Stores. This leads to privilege escalation on the local host.

CVE-2020-21605
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.

CVE-2020-12720
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

CVE-2020-27019
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.

CVE-2020-12252
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.

CVE-2020-3656
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI devices in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, Kamorta, MDM9607, MSM8917, MSM8953, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM710, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

CVE-2020-25013
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

CVE-2020-15488
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Re:Desk 2.3 allows insecure file upload.

CVE-2020-28015
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.

CVE-2020-20902
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denominator of pseudo-normalized correlation R'(0), that could result in disclosure of information.

CVE-2020-11601
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unauthorized access to applications in the Secure Folder via floating icons. The Samsung ID is SVE-2019-16195 (April 2020).

CVE-2020-11494
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.

CVE-2020-16024
Chrome General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-16303
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

CVE-2020-11686
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.