3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-16040
Chrome General
N/A
UNKNOWN
EPSS
75.1%
2020 3 PoCs

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-29368
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.

CVE-2020-10770
keycloak General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 CWE-918 3 PoCs

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

CVE-2020-6921
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-8256
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
3.9%
2020 CWE-611 3 PoCs

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

CVE-2020-15647
Firefox for General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVE-2020-6805
Thunderbird General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-28845
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.

CVE-2020-13844
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."

CVE-2020-22983
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

CVE-2020-11220
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2020-9362
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.

CVE-2020-16258
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

CVE-2020-16211
Advantech WebAccess HMI Designer General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-125 1 PoC

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

CVE-2020-5812
Tenable Nessus AMI General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Nessus AMI versions 8.12.0 and earlier were found to either not validate, or incorrectly validate, a certificate which could allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

CVE-2020-8781
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.

CVE-2020-13813
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.

CVE-2020-6445
Chrome General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVE-2020-25749
Software Genérico General
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

CVE-2020-24386
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).