3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7788
ini General
7.3
HIGH
EPSS
0.3%
2020 2 PoCs

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-1773
((OTRS)) Community Edition General
7.3
HIGH
EPSS
0.5%
2020 CWE-331 1 PoC

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVE-2020-2506
🔥 KEV Helpdesk General
7.3
HIGH
EPSS
18.0%
2020 CWE-284 1 PoC

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-28503
copy-props General
7.3
HIGH
EPSS
0.6%
2020 2 PoCs

The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.

CVE-2020-10627
Omnipod Insulin Management System General
7.3
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

CVE-2020-28429
geojson2kml General ⚡ nuclei
7.3
HIGH
EPSS
84.8%
2020 1 PoC

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

CVE-2020-7795
get-npm-package-version General
7.3
HIGH
EPSS
4.3%
2020 1 PoC

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

CVE-2020-28426
kill-process-on-port General
7.3
HIGH
EPSS
6.9%
2020 1 PoC

All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

CVE-2020-28471
properties-reader General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package properties-reader before 2.2.0.

CVE-2020-28455
markdown-it-toc General
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

CVE-2020-6293
SAP NetWeaver (Knowledge Management) General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

CVE-2020-7260
Mcafee Application and Change Control (MACC) General
7.3
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

CVE-2020-28461
js-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-28895
Software Genérico General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVE-2020-6191
SAP Landscape Management General
7.2
HIGH
EPSS
0.4%
2020 1 PoC

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.

CVE-2020-37078
i-doit Open Source CMDB General
7.2
HIGH
EPSS
0.1%
2020 CWE-73 1 PoC

i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's filesystem.

CVE-2020-8218
🔥 KEV Pulse Connect Secure General
7.2
HIGH
EPSS
91.1%
2020 CWE-94 3 PoCs

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

CVE-2020-8103
Bitdefender Antivirus Free General
7.2
HIGH
EPSS
2.1%
2020 CWE-59 1 PoC

A vulnerability in the improper handling of symbolic links in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issue affects Bitdefender Antivirus Free versions prior to 1.0.17.178.

CVE-2020-7329
MVISION Endpoint ePO extension General
7.2
HIGH
EPSS
0.7%
2020 CWE-918 1 PoC

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.