578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-9883
iOS Cloud Windows
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

CVE-2020-17362
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.9%
2020 0 PoCs

search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.

CVE-2020-9343
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the implementation doesn't limit the parsing of nested JSON structures. If a victim visits an attacker-controlled website, this vulnerability can be exploited via WebSocket data with a deeply nested JSON array.

CVE-2020-1281
Windows Windows
N/A
UNKNOWN
EPSS
25.8%
2020 1 PoC

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.

CVE-2020-35145
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.

CVE-2020-11514
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
65.5%
2020 0 PoCs

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

CVE-2020-13487
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.

CVE-2020-25718
samba Windows
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-862 1 PoC

A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.

CVE-2020-1048
Windows Windows
N/A
UNKNOWN
EPSS
72.8%
2020 5 PoCs

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.

CVE-2020-12895
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service.

CVE-2020-12902
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

CVE-2020-0624
Windows 10 Version 1903 for 32-bit Systems Windows
N/A
UNKNOWN
EPSS
14.5%
2020 1 PoC

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.

CVE-2020-27212
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.

CVE-2020-36229
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.0%
2020 3 PoCs

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring, resulting in denial of service.

CVE-2020-7228
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.

CVE-2020-13865
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a crafted link in the custom URL or by applying custom attributes.

CVE-2020-14158
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity of RF packets that are exchanged with an alarm panel. This makes it easier to conduct wAppLoxx authentication-bypass attacks.

CVE-2020-8144
UniFi Video Controller (for Windows 7/8/10 x64) Windows
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-22 1 PoC

The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware update information. If the version field contains ..\ character sequences, the destination file path to save the firmware can be manipulated to be outside the intended destination directory tree. Fixed in UniFi Video Controller v3.10.3 and newer.