438 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2020-14750
🔥 KEV WebLogic Server Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 3 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-9054
🔥 KEV NAS326 Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 CWE-78 4 PoCs

Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does n

CVE-2020-0646
🔥 KEV Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 General
9.8
CRITICAL
EPSS
93.9%
2020 1 PoC

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

CVE-2020-1938
🔥 KEV Apache Tomcat Web
9.8
CRITICAL
EPSS
94.5%
2020 29 PoCs

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not re

CVE-2020-14882
🔥 KEV WebLogic Server Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2020 38 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-10987
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2020 1 PoC

The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

CVE-2020-2883
🔥 KEV WebLogic Server Database
9.8
CRITICAL
EPSS
94.4%
2020 9 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-3992
🔥 KEV VMware ESXi General
9.8
CRITICAL
EPSS
90.9%
2020 1 PoC

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine may be able to trigger a use-after-free in the OpenSLP service resulting in remote code execution.

CVE-2020-15415
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2020 0 PoCs

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CVE-2020-17496
🔥 KEV Software Genérico DevOps ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2020 4 PoCs

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

CVE-2020-8657
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.9%
2020 1 PoC

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

CVE-2020-29574
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
12.0%
2020 1 PoC

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CVE-2020-11651
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.2%
2020 14 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVE-2020-3161
🔥 KEV Cisco IP phone Web Networking
9.8
CRITICAL
EPSS
87.1%
2020 CWE-20 3 PoCs

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVE-2020-2555
🔥 KEV WebCenter Portal Database
9.8
CRITICAL
EPSS
93.1%
2020 15 PoCs

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-26919
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2020 1 PoC

NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

CVE-2020-8644
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2020 3 PoCs

PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.