2786 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2020-7047
Software Genérico Web Windows
9.9
CRITICAL
EPSS
1.7%
2020 1 PoC

The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.

CVE-2020-13126
Software Genérico Web Windows
9.9
CRITICAL
EPSS
67.0%
2020 2 PoCs

An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.

CVE-2020-28464
djv Web
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

CVE-2020-3247
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
46.1%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-10148
🔥 KEV Orion Platform Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 CWE-288 4 PoCs

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

CVE-2020-17463
🔥 KEV Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.5%
2020 2 PoCs

FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

CVE-2020-2953
Retail Customer Management and Segmentation Foundation Web Database
9.8
CRITICAL
EPSS
1.6%
2020 1 PoC

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions). The supported version that is affected is 18.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:

CVE-2020-36084
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.

CVE-2020-2950
Oracle Business Intelligence Enterprise Edition Web Database
9.8
CRITICAL
EPSS
85.9%
2020 2 PoCs

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CV

CVE-2020-7719
locutus Web
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

CVE-2020-6139
OS4Ed Web Database
9.8
CRITICAL
EPSS
0.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The username_stf_email parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-12641
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.1%
2020 2 PoCs

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

CVE-2020-3239
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
38.7%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-10826
Software Genérico Web
9.8
CRITICAL
EPSS
30.0%
2020 2 PoCs

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

CVE-2020-3243
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
90.2%
2020 CWE-20 2 PoCs

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-36849
AIT CSV import/export Web Windows
9.8
CRITICAL
EPSS
84.5%
2020 CWE-434 1 PoC

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for unauthorized attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2020-10828
Software Genérico Web
9.8
CRITICAL
EPSS
13.4%
2020 2 PoCs

A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVE-2020-6140
OS4Ed Web Database
9.8
CRITICAL
EPSS
0.7%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the password reset functionality of OS4Ed openSIS 7.3. The password_stf_email parameter in the password reset page /opensis/ResetUserInfo.php is vulnerable to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-10825
Software Genérico Web
9.8
CRITICAL
EPSS
5.5%
2020 2 PoCs

A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).

CVE-2020-2961
Enterprise Manager Base Platform Web Database
9.8
CRITICAL
EPSS
1.6%
2020 1 PoC

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework (Oracle OHS)). Supported versions that are affected are 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).