3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26989
JT2Go General
N/A
UNKNOWN
EPSS
1.8%
2020 CWE-121 1 PoC

A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11892)

CVE-2020-10569
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938

CVE-2020-9024
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.

CVE-2020-0240
Android General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594

CVE-2020-19038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

File Deletion vulnerability in Halo 0.4.3 via delBackup.

CVE-2020-13472
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.

CVE-2020-24115
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

CVE-2020-12351
BlueZ General
N/A
UNKNOWN
EPSS
2.9%
2020 2 PoCs

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-21601
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.

CVE-2020-13866
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

CVE-2020-8141
dot General
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-94 1 PoC

The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.

CVE-2020-11532
Software Genérico General
N/A
UNKNOWN
EPSS
89.8%
2020 2 PoCs

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

CVE-2020-19724
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.

CVE-2020-13804
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin.

CVE-2020-7483
TriStation TS1131 (v4.0.0 to v4.9.0, v4.10.0) General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. The 'password' feature is an additional optional check performed by TS1131 that it is connected to a specific controller. This data is sent as clear text and is visible on the network. This feature is not present in TriStation 1131 versions v4.9.1 and v4.10.1 through current. Therefore, the vulnerability is not present in these versions.

CVE-2020-6917
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-6468
Chrome General
N/A
UNKNOWN
EPSS
42.5%
2020 2 PoCs

Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-24579
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2020 2 PoCs

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.

CVE-2020-15867
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.8%
2020 1 PoC

The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a "Product UI does not Warn User of Unsafe Actions" issue.