33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13340
GitLab DevOps Web
8.7
HIGH
EPSS
1.5%
2020 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

CVE-2020-37009
MedDream PACS Server Web
8.7
HIGH
EPSS
0.3%
2020 CWE-434 1 PoC

MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system commands with elevated privileges.

CVE-2020-15255
timetracker General
8.7
HIGH
EPSS
1.2%
2020 CWE-74 2 PoCs

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

CVE-2020-36973
PDW File Browser Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.

CVE-2020-37173
AVideo Platform Web
8.7
HIGH
EPSS
0.1%
2020 CWE-359 1 PoC

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

CVE-2020-36872
BACnet Test Server General
8.7
HIGH
EPSS
0.3%
2020 CWE-400 2 PoCs

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a malformed BVLC Length value to trigger an access violation and crash the application, resulting in a denial of service.

CVE-2020-36910
SMP-8000QD General
8.7
HIGH
EPSS
0.5%
2020 CWE-78 2 PoCs

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

CVE-2020-37116
GUnet OpenEclass Web Database
8.7
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.

CVE-2020-37214
Voyager General
8.7
HIGH
EPSS
0.5%
2020 CWE-22 1 PoC

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

CVE-2020-4062
Conjur OSS Helm Chart DevOps
8.7
HIGH
EPSS
0.4%
2020 CWE-284 1 PoC

In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the attacker's privileges to assume full control. A malicious actor who knows the IP address and port number of the Postgres database and has access into the Kubernetes cluster where Conjur runs can gain full read & write access to the Postgres database. This enables the attacker to write a policy that allows full access to

CVE-2020-36909
SnapGear Management Console SG560 General
8.7
HIGH
EPSS
0.2%
2020 CWE-22 2 PoCs

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.

CVE-2020-36950
Laravel Nova DevOps Web
8.7
HIGH
EPSS
0.1%
2020 CWE-770 1 PoC

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.

CVE-2020-36882
DiskBoss General
8.7
HIGH
EPSS
0.3%
2020 CWE-434 1 PoC

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.

CVE-2020-5232
@ensdomains/ens General
8.7
HIGH
EPSS
0.3%
2020 CWE-285 1 PoC

A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.

CVE-2020-36969
M/Monit Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 1 PoC

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.

CVE-2020-36920
iDS6 DSSPro Digital Signage System Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

CVE-2020-36915
SignEdje Digital Signage Player Networking
8.7
HIGH
EPSS
0.1%
2020 CWE-798 2 PoCs

Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.

CVE-2020-37085
VirtualTablet Server General
8.7
HIGH
EPSS
0.1%
2020 CWE-770 2 PoCs

VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.

CVE-2020-36878
ReQuest Serious Play Media Player General
8.7
HIGH
EPSS
0.0%
2020 CWE-73 2 PoCs

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.

CVE-2020-37182
Redir General
8.7
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length checking to overwrite memory and cause a segmentation fault, resulting in program termination.