578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-14999
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data.

CVE-2020-13892
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The SportsPress plugin before 2.7.2 for WordPress allows XSS.

CVE-2020-1043
Windows Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042.

CVE-2020-1042
Windows Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1043.

CVE-2020-17365
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

CVE-2020-11492
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
5.6%
2020 4 PoCs

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.

CVE-2020-0801
Windows Windows
N/A
UNKNOWN
EPSS
13.4%
2020 1 PoC

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0807, CVE-2020-0809, CVE-2020-0869.

CVE-2020-8254
Pulse Secure Desktop Client Windows
N/A
UNKNOWN
EPSS
2.4%
2020 CWE-23 2 PoCs

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse clients and Pulse Connect Secure, see below recommendation(s):Disable Dynamic certificate trust for PDC.

CVE-2020-11522
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.

CVE-2020-15591
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.3%
2020 1 PoC

fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).

CVE-2020-0728
Windows Windows
N/A
UNKNOWN
EPSS
13.9%
2020 4 PoCs

An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.

CVE-2020-0642
Windows Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624.

CVE-2020-1036
Windows Server Windows
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

CVE-2020-9335
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-11525
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read.

CVE-2020-7581
Opcenter Execution Discrete Windows
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-428 1 PoC

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMOCODE ES V15.1 (All versions < V15.1 Update 4), SIMOCODE ES V16 (All vers

CVE-2020-13110
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.

CVE-2020-13396
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.

CVE-2020-9455
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.

CVE-2020-36221
Software Genérico Windows
N/A
UNKNOWN
EPSS
57.5%
2020 3 PoCs

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).