3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6081
3S General
9.9
CRITICAL
EPSS
0.9%
2020 1 PoC

An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2020-15149
NodeBB General
9.9
CRITICAL
EPSS
0.4%
2020 CWE-269 2 PoCs

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation event due via an account takeover. As a workaround you may cherry-pick the following commit from the project's repository to your running instance of NodeBB: 16cee1b03ba3eee177834a1fdac4aa8a12b39d2a. This is fixed in version 1.14.3.

CVE-2020-7703
nis-utils General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.

CVE-2020-6242
SAP Business Objects Business Intelligence Platform (Live Data Connect) General
9.8
CRITICAL
EPSS
0.2%
2020 1 PoC

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Authentication Check.

CVE-2020-25020
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2020 2 PoCs

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

CVE-2020-13556
EIP Stack Group General
9.8
CRITICAL
EPSS
2.6%
2020 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2020-15415
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2020 0 PoCs

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CVE-2020-7726
safe-object2 General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

CVE-2020-3952
🔥 KEV VMware vCenter Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

CVE-2020-12504
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.6%
2020 CWE-912 5 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-7707
property-expr General
9.8
CRITICAL
EPSS
2.1%
2020 3 PoCs

The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

CVE-2020-28439
corenlp-js-prefab General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

CVE-2020-12501
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.9%
2020 CWE-798 6 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

CVE-2020-7794
buns General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).

CVE-2020-28446
ntesseract General
9.8
CRITICAL
EPSS
11.6%
2020 1 PoC

The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

CVE-2020-0646
🔥 KEV Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 General
9.8
CRITICAL
EPSS
93.9%
2020 1 PoC

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVE-2020-7706
connie-lang General
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

CVE-2020-7702
Templ8 General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

CVE-2020-12500
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.8%
2020 CWE-306 4 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.