578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-18169
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided by the Host OS. See reference document for more details

CVE-2020-9495
Apache Archiva Web Windows
N/A
UNKNOWN
EPSS
27.5%
2020 1 PoC

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

CVE-2020-27208
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

CVE-2020-0887
Windows Windows
N/A
UNKNOWN
EPSS
13.9%
2020 1 PoC

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.

CVE-2020-1885
Oculus Desktop Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Writing to an unprivileged file from a privileged OVRRedir.exe process in Oculus Desktop before 1.44.0.32849 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file.

CVE-2020-1313
Windows 10 Version 1909 for 32-bit Systems Windows
N/A
UNKNOWN
EPSS
81.6%
2020 2 PoCs

An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.

CVE-2020-8948
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.

CVE-2020-10195
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain syste

CVE-2020-6859
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.

CVE-2020-13397
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.

CVE-2020-6850
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.

CVE-2020-5962
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

CVE-2020-0981
Windows 10 Version 1909 for 32-bit Systems Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to a sandbox escape.The update addresses the vulnerability by correcting how Windows handles token relationships, aka 'Windows Token Security Feature Bypass Vulnerability'.

CVE-2020-15020
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.

CVE-2020-13693
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
41.3%
2020 1 PoC

An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

CVE-2020-6849
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.3%
2020 2 PoCs

The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.

CVE-2020-9372
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
19.3%
2020 2 PoCs

The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code execution via CSV injection.

CVE-2020-13938
Apache HTTP Server Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

CVE-2020-16011
Chrome Windows
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-12933
AMD Graphics Driver for Windows Web Windows
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-125 1 PoC

A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTEscape API request can cause an out-of-bounds read in Windows OS kernel memory area. This vulnerability can be triggered from a non-privileged account.