3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-3843
iOS-1 General
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4.7, watchOS 5.3.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2020-0543
Intel(R) Processors General
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-28367
cmd/go General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVE-2020-8636
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 2 PoCs

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

CVE-2020-10846
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

CVE-2020-26108
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

CVE-2020-35530
LibRaw General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVE-2020-24377
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

CVE-2020-29655
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker might be able to influence the appearance of the login page, aka text injection.

CVE-2020-14008
Software Genérico General
N/A
UNKNOWN
EPSS
46.2%
2020 3 PoCs

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

CVE-2020-6794
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

CVE-2020-8004
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2020 1 PoC

STMicroelectronics STM32F1 devices have Incorrect Access Control.

CVE-2020-22623
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information.

CVE-2020-13245
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

CVE-2020-10939
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

CVE-2020-5187
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

CVE-2020-11299
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-12880
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

CVE-2020-11938
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.