578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-13884
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-15363
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
14.2%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

CVE-2020-5794
Nessus Network Monitor Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbitrary code by copying user-supplied files to a specially constructed path in a specifically named user directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.

CVE-2020-3653
Snapdragon Compute, Snapdragon Connectivity Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850

CVE-2020-9019
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.

CVE-2020-36224
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.5%
2020 4 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVE-2020-29304
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

CVE-2020-8290
Backblaze Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-269 3 PoCs

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

CVE-2020-9466
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.

CVE-2020-15931
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.3%
2020 2 PoCs

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

CVE-2020-11524
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

CVE-2020-7107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2020-9290
Fortinet FortiClient for Windows Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

CVE-2020-26141
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.

CVE-2020-24948
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
23.4%
2020 2 PoCs

The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

CVE-2020-5976
NVIDIA GeForce NOW Application Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.

CVE-2020-1032
Windows Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

CVE-2020-8771
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 1 PoC

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

CVE-2020-5975
NVIDIA GeForce NOW Application Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.

CVE-2020-15663
Firefox Windows
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 6