2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36768
NESP2 Networking Database
7.3
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

CVE-2020-9410
TIBCO JasperReports Library Cloud
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an attacker to exploit HTML injection to gain full control of a web interface containing the output of the report generator component with the privileges of any user that views the affected report(s). The attacker can theoretically exploit this vulnerability when other users view a mal

CVE-2020-12525
fdtCONTAINER Component DevOps
7.3
HIGH
EPSS
0.1%
2020 CWE-502 1 PoC

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

CVE-2020-7737
safetydance General
7.3
HIGH
EPSS
0.4%
2020 2 PoCs

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

CVE-2020-36542
Demokratian Web
7.3
HIGH
EPSS
0.5%
2020 CWE-269 3 PoCs

A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2020-28458
datatables.net Web
7.3
HIGH
EPSS
1.2%
2020 2 PoCs

All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

CVE-2020-28895
Software Genérico General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVE-2020-8903
guest-oslogin Cloud
7.3
HIGH
EPSS
0.1%
2020 CWE-276 1 PoC

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possibl

CVE-2020-7778
systeminformation General
7.3
HIGH
EPSS
1.1%
2020 1 PoC

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

CVE-2020-14724
Solaris Operating System Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:

CVE-2020-28495
total.js General
7.3
HIGH
EPSS
6.1%
2020 1 PoC

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVE-2020-28455
markdown-it-toc General
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

CVE-2020-28471
properties-reader General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package properties-reader before 2.2.0.

CVE-2020-1773
((OTRS)) Community Edition General
7.3
HIGH
EPSS
0.5%
2020 CWE-331 1 PoC

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVE-2020-28426
kill-process-on-port General
7.3
HIGH
EPSS
6.9%
2020 1 PoC

All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

CVE-2020-7795
get-npm-package-version General
7.3
HIGH
EPSS
4.3%
2020 1 PoC

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

CVE-2020-2787
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d

CVE-2020-28429
geojson2kml General ⚡ nuclei
7.3
HIGH
EPSS
84.8%
2020 1 PoC

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

CVE-2020-10627
Omnipod Insulin Management System General
7.3
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

CVE-2020-28503
copy-props General
7.3
HIGH
EPSS
0.6%
2020 2 PoCs

The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.