578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-35037
Events Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

CVE-2020-6010
LearnPress Wordpress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
45.5%
2020 1 PoC

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

CVE-2020-36504
Wp-Pro-Quiz Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-352 2 PoCs

The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog

CVE-2020-8772
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 1 PoC

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVE-2020-36225
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.8%
2020 4 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVE-2020-0609
Windows Server Windows
N/A
UNKNOWN
EPSS
88.8%
2020 2 PoCs

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

CVE-2020-12798
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.

CVE-2020-11727
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.

CVE-2020-8240
Pulse Secure Desktop Client Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

CVE-2020-1021
Windows Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1082, CVE-2020-1088.

CVE-2020-11548
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.7%
2020 1 PoC

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

CVE-2020-29047
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
84.6%
2020 1 PoC

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

CVE-2020-1958
Apache Druid Web Windows
N/A
UNKNOWN
EPSS
15.6%
2020 1 PoC

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.

CVE-2020-15537
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.

CVE-2020-3652
Snapdragon Compute, Snapdragon Connectivity Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length of variable received. in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850

CVE-2020-12054
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.6%
2020 2 PoCs

The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold Photography PRO, Intuitive PRO, Devotepress PRO, Clean Blocks PRO, Foodoholic PRO, Catch Mag PRO, Catch Wedding PRO, and Higher Education PRO.

CVE-2020-12894
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.

CVE-2020-29045
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
35.2%
2020 1 PoC

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

CVE-2020-12427
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

CVE-2020-8239
Pulse Secure Desktop Cient Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.