3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-27556
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.

CVE-2020-29655
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker might be able to influence the appearance of the login page, aka text injection.

CVE-2020-14008
Software Genérico General
N/A
UNKNOWN
EPSS
46.2%
2020 3 PoCs

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

CVE-2020-6794
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.

CVE-2020-8004
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2020 1 PoC

STMicroelectronics STM32F1 devices have Incorrect Access Control.

CVE-2020-0513
Intel(R) Graphics Drivers Advisory General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Out of bounds write for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24366
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

CVE-2020-36365
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
9.7%
2020 0 PoCs

Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.

CVE-2020-22623
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information.

CVE-2020-13245
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

CVE-2020-10939
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

CVE-2020-5187
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

CVE-2020-11299
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-12880
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

CVE-2020-11938
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.

CVE-2020-6443
Chrome General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.

CVE-2020-24985
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.

CVE-2020-0226
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994