3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-36909
SnapGear Management Console SG560 General
8.7
HIGH
EPSS
0.2%
2020 CWE-22 2 PoCs

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.

CVE-2020-37182
Redir General
8.7
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length checking to overwrite memory and cause a segmentation fault, resulting in program termination.

CVE-2020-37157
DBPower C300 HD Camera General
8.7
HIGH
EPSS
0.0%
2020 CWE-306 1 PoC

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.

CVE-2020-36876
ReQuest Serious Play Pro General
8.7
HIGH
EPSS
0.1%
2020 CWE-532 2 PoCs

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.

CVE-2020-36878
ReQuest Serious Play Media Player General
8.7
HIGH
EPSS
0.0%
2020 CWE-73 2 PoCs

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.

CVE-2020-37085
VirtualTablet Server General
8.7
HIGH
EPSS
0.1%
2020 CWE-770 2 PoCs

VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.

CVE-2020-15255
timetracker General
8.7
HIGH
EPSS
1.2%
2020 CWE-74 2 PoCs

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

CVE-2020-37104
ASTPP General
8.7
HIGH
EPSS
0.1%
2020 CWE-538 1 PoC

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

CVE-2020-36948
VestaCP General
8.7
HIGH
EPSS
0.3%
2020 CWE-863 2 PoCs

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.

CVE-2020-36925
Arteco Web Client DVR/NVR General
8.7
HIGH
EPSS
0.6%
2020 CWE-331 2 PoCs

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

CVE-2020-37069
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-36887
Fusion Digital Signage General
8.7
HIGH
EPSS
0.1%
2020 CWE-312 2 PoCs

SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information.

CVE-2020-36899
QiHang Media Web Digital Signage General
8.7
HIGH
EPSS
0.5%
2020 CWE-530 2 PoCs

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

CVE-2020-37146
Aptina AR0130 960P 1.3MP Camera General
8.7
HIGH
EPSS
0.0%
2020 CWE-306 1 PoC

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system settings.

CVE-2020-37097
EW-7438RPn Mini General
8.7
HIGH
EPSS
0.1%
2020 CWE-522 1 PoC

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

CVE-2020-36850
JSS React Sample Application General
8.7
HIGH
EPSS
0.1%
2020 CWE-200 1 PoC

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.

CVE-2020-37034
HelloWeb General
8.7
HIGH
EPSS
0.2%
2020 CWE-22 1 PoC

HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.

CVE-2020-5232
@ensdomains/ens General
8.7
HIGH
EPSS
0.3%
2020 CWE-285 1 PoC

A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.

CVE-2020-37094
EspoCRM General
8.7
HIGH
EPSS
0.4%
2020 CWE-639 1 PoC

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

CVE-2020-36896
QiHang Media Web Digital Signage General
8.7
HIGH
EPSS
1.4%
2020 CWE-522 2 PoCs

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.