3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26919
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2020 1 PoC

NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

CVE-2020-36239
Jira Data Center General
9.8
CRITICAL
EPSS
16.2%
2020 CWE-862 1 PoC

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting a

CVE-2020-28597
Epignosis General
9.8
CRITICAL
EPSS
0.4%
2020 CWE-337 1 PoC

A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.

CVE-2020-29007
Software Genérico General
9.8
CRITICAL
EPSS
17.4%
2020 1 PoC

The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted {{Image data to generate musical scores containing malicious code.

CVE-2020-28439
corenlp-js-prefab General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

CVE-2020-12504
P+F Comtrol RocketLinx General
9.8
CRITICAL
EPSS
0.6%
2020 CWE-912 5 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

CVE-2020-13571
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the SGI RLE decompression functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-25020
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2020 2 PoCs

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

CVE-2020-4450
WebSphere Application Server General
9.8
CRITICAL
EPSS
71.9%
2020 1 PoC

IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects. IBM X-Force ID: 181231.

CVE-2020-7721
node-oojs General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

CVE-2020-7702
Templ8 General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

CVE-2020-3931
Door Access Control Device General
9.8
CRITICAL
EPSS
1.7%
2020 CWE-120 1 PoC

Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.

CVE-2020-7781
connection-tester General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:

CVE-2020-7707
property-expr General
9.8
CRITICAL
EPSS
2.1%
2020 3 PoCs

The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

CVE-2020-0646
🔥 KEV Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 General
9.8
CRITICAL
EPSS
93.9%
2020 1 PoC

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVE-2020-23583
Software Genérico General
9.8
CRITICAL
EPSS
7.8%
2020 2 PoCs

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.

CVE-2020-7786
macfromip General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.

CVE-2020-6069
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 2 PoCs

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG jpegread precision parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-3992
🔥 KEV VMware ESXi General
9.8
CRITICAL
EPSS
90.9%
2020 1 PoC

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CVE-2020-6066
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 2 PoCs

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG SOFx parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.