578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-5992
NVIDIA GeForce NOW Application Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.

CVE-2020-8145
UniFi Video Controller (for Windows 7/8/10 x64) Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.

CVE-2020-7906
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

CVE-2020-12243
Software Genérico Windows
N/A
UNKNOWN
EPSS
10.8%
2020 2 PoCs

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

CVE-2020-13699
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
72.9%
2020 1 PoC

TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a victim to send an NTLM authentication request and either relay the request or capture the hash for offline password cracking. This affects teamviewer10, teamviewer8, teamviewerapi, tvchat1, tvcontrol1, tvfiletransfer1, tvjoinv8, tvpresent1, tvsendfile1, tvsqcustomer1, tvsqsupport1, tvvideocall1, and tvvpn1. The issue is fixed in 8.0.258861, 9.0.258860, 10.0.25

CVE-2020-8594
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].

CVE-2020-8498
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

CVE-2020-7239
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent.

CVE-2020-5766
SRS Simple Hits Counter Plugin for WordPress Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
39.1%
2020 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

CVE-2020-36227
Software Genérico Windows
N/A
UNKNOWN
EPSS
63.6%
2020 3 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in denial of service.

CVE-2020-14092
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.7%
2020 1 PoC

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-11547
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2020 1 PoC

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

CVE-2020-11930
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

CVE-2020-0557
Intel(R) PROSet/Wireless WiFi Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-11497
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

CVE-2020-8950
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.0%
2020 2 PoCs

The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.

CVE-2020-35488
Software Genérico Windows
N/A
UNKNOWN
EPSS
19.4%
2020 1 PoC

The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.)

CVE-2020-12982
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

CVE-2020-12673
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.6%
2020 1 PoC

In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.

CVE-2020-9334
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.