578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-12983
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or denial of service.

CVE-2020-13640
Software Genérico Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
73.9%
2020 3 PoCs

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

CVE-2020-9497
Apache Guacamole Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.

CVE-2020-9457
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

CVE-2020-27020
Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

CVE-2020-11526
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.

CVE-2020-7587
Opcenter Execution Discrete Windows
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-400 1 PoC

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Production Suite (All versions < V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V1

CVE-2020-16140
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The search functionality of the Greenmart theme 2.4.2 for WordPress is vulnerable to XSS.

CVE-2020-8276
https://github.com/brave/brave-core Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-312 1 PoC

The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the timestamp for incognito windows excluding Tor windows. Note that if a user has P3A enabled, the timestamp is not sent to Brave's server, but rather a value from:Used in last 24hUsed in last week but not 24hUsed in last 28 days but not weekEver used but not in last 28 daysNever usedThe privacy risk is low because a local attacker with disk access cannot tell if th

CVE-2020-28032
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
25.8%
2020 2 PoCs

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVE-2020-1015
Windows Windows
N/A
UNKNOWN
EPSS
13.0%
2020 1 PoC

An elevation of privilege vulnerability exists in the way that the User-Mode Power Service (UMPS) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1011.

CVE-2020-0802
Windows Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.

CVE-2020-12431
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).

CVE-2020-9456
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.

CVE-2020-9454
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

CVE-2020-5147
SonicWall NetExtender Networking Windows
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-428 1 PoC

SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impact SonicWall NetExtender Windows client version 10.2.300 and earlier.

CVE-2020-12903
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service.

CVE-2020-7104
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.6%
2020 1 PoC

The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.