1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7782
spritesheet-js General
9.8
CRITICAL
EPSS
0.6%
2020 1 PoC

This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.

CVE-2020-10257
Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
66.6%
2020 1 PoC

The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.

CVE-2020-16846
🔥 KEV Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 2 PoCs

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

CVE-2020-0618
🔥 KEV Microsoft SQL Server Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2020 6 PoCs

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

CVE-2020-10824
Software Genérico Web
9.8
CRITICAL
EPSS
5.5%
2020 2 PoCs

A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).

CVE-2020-3252
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
9.0%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-26799
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.

CVE-2020-6068
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 2 PoCs

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-5722
🔥 KEV Grandstream UCM6200 Series Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2020 3 PoCs

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

CVE-2020-7701
madlib-object-utils General
9.8
CRITICAL
EPSS
1.1%
2020 2 PoCs

madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

CVE-2020-5847
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.4%
2020 3 PoCs

Unraid through 6.8.0 allows Remote Code Execution.

CVE-2020-7717
dot-notes General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

CVE-2020-28443
sonar-wrapper General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

CVE-2020-37000
Free MP3 CD Ripper Windows
9.8
CRITICAL
EPSS
0.2%
2020 CWE-121 1 PoC

Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter technique to achieve remote code execution on vulnerable Windows systems.

CVE-2020-13561
Accusoft General
9.8
CRITICAL
EPSS
0.7%
2020 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the TIFF parser of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-6063
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-6065
Accusoft General
9.8
CRITICAL
EPSS
2.9%
2020 1 PoC

An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2020-28447
xopen General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

CVE-2020-28423
monorepo-build General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package monorepo-build.