578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-28976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.2%
2020 1 PoC

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

CVE-2020-11415
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

CVE-2020-12898
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

CVE-2020-8146
UniFi Video Controller (for Windows 7/8/10 x64) Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the SafeDllSearchMode in the windows registry when installing UniFi-Video controller. Affected Products: UniFi Video Controller v3.10.2 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.10.3 and newer.

CVE-2020-24227
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password.

CVE-2020-12393
Firefox ESR Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

CVE-2020-8230
Desktop Client Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-119 2 PoCs

A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.

CVE-2020-25719
samba Windows
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-287 1 PoC

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise.

CVE-2020-12920
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck.

CVE-2020-26050
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.

CVE-2020-36505
Delete All Comments Easily Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-352 3 PoCs

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

CVE-2020-5752
Druva inSync Windows Client Windows
N/A
UNKNOWN
EPSS
7.6%
2020 5 PoCs

Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

CVE-2020-36228
Software Genérico Windows
N/A
UNKNOWN
EPSS
73.5%
2020 3 PoCs

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

CVE-2020-13885
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-23762
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.

CVE-2020-14962
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.

CVE-2020-28038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

WordPress before 5.5.2 allows stored XSS via post slugs.

CVE-2020-8799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.

CVE-2020-25744
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.

CVE-2020-13884
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.