2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-4958
Security Identity Governance and Intelligence General
7.4
HIGH
EPSS
0.3%
2020 1 PoC

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.

CVE-2020-14535
Commerce Platform Web Database
7.4
HIGH
EPSS
1.5%
2020 1 PoC

Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Service Center. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Service Center accessible data as well as unauthorized access to critical data or complete access to all Oracle Commer

CVE-2020-25638
hibernate-core Web Database
7.4
HIGH
EPSS
0.7%
2020 CWE-89 4 PoCs

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-35947
Software Genérico Web Windows
7.4
HIGH
EPSS
0.5%
2020 2 PoCs

An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

CVE-2020-36838
Facebook Chat Plugin – Live Chat Plugin for WordPress Web Windows
7.4
HIGH
EPSS
0.0%
2020 CWE-284 1 PoC

The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own Facebook Messenger account to any site running the vulnerable plugin and engage in chats with site visitors on affected sites.

CVE-2020-7278
McAfee Endpoint Security (ENS) Networking Windows
7.4
HIGH
EPSS
0.2%
2020 CWE-284 1 PoC

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.

CVE-2020-26233
Git-Credential-Manager-Core Windows
7.3
HIGH
EPSS
15.6%
2020 CWE-706 2 PoCs

Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will first clone the top-level repository and then recursively clone all submodules by starting new Git processes from the top-level working directory. If a malicious git.exe executable is present in the top-level repository then this binary will be started by Git Credential Manager Core when attempting to read configuration, and not git.exe as

CVE-2020-1319
Windows 10 Version 1803 Windows
7.3
HIGH
EPSS
12.4%
2020 1 PoC

<p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>Exploitation of the vulnerability requires that a program process a specially crafted image file.</p> <p>The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory.</p>

CVE-2020-28472
@aws-sdk/shared-ini-file-loader Cloud
7.3
HIGH
EPSS
1.7%
2020 4 PoCs

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-14543
Hospitality Reporting and Analytics Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVS

CVE-2020-7679
casperjs General
7.3
HIGH
EPSS
0.8%
2020 3 PoCs

In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

CVE-2020-2786
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d

CVE-2020-3556
Cisco AnyConnect Secure Mobility Client Networking
7.3
HIGH
EPSS
0.2%
2020 CWE-20 1 PoC

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could exploit this vulnerability by sending crafted IPC messages to the AnyConnect client IPC listener. A successful exploit could allow an attacker to cause the targeted AnyConnect user to execute a script. This script would execute with the privileges of the targeted AnyConnect user.

CVE-2020-28495
total.js General
7.3
HIGH
EPSS
6.1%
2020 1 PoC

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVE-2020-14561
Hospitality Reporting and Analytics Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVS

CVE-2020-2784
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partia

CVE-2020-7736
bmoor General
7.3
HIGH
EPSS
0.8%
2020 2 PoCs

The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

CVE-2020-28459
markdown-it-decorate Web
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

CVE-2020-28433
node-latex-pdf General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package node-latex-pdf.

CVE-2020-14724
Solaris Operating System Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I: