1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-28599
Openscad General
8.8
HIGH
EPSS
1.4%
2020 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-27347
tmux General
8.8
HIGH
EPSS
0.3%
2020 CWE-121 1 PoC

In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

CVE-2020-7266
McAfee VirusScan Enterprise (VSE) for Windows Windows
8.8
HIGH
EPSS
0.0%
2020 CWE-274 1 PoC

Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVE-2020-36945
WebDamn User Registration & Login System with User Panel Database
8.8
HIGH
EPSS
0.4%
2020 CWE-89 1 PoC

WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel.

CVE-2020-13581
SoftMaker General
8.8
HIGH
EPSS
0.3%
2020 CWE-122 1 PoC

In SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data from a particular record type into a buffer that is smaller than the size used for the copy which will cause a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability.

CVE-2020-11925
Software Genérico General
8.8
HIGH
EPSS
0.3%
2020 1 PoC

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.

CVE-2020-35789
Software Genérico Cloud
8.8
HIGH
EPSS
0.8%
2020 1 PoC

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

CVE-2020-36898
QiHang Media Web Digital Signage General
8.8
HIGH
EPSS
15.0%
2020 CWE-22 2 PoCs

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. Attackers can exploit the 'data' parameter by sending a POST request with file paths to delete arbitrary files with web server permissions using directory traversal sequences.

CVE-2020-7752
systeminformation Web
8.8
HIGH
EPSS
3.1%
2020 2 PoCs

This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.

CVE-2020-13493
Pixar General
8.8
HIGH
EPSS
0.3%
2020 CWE-122 2 PoCs

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

CVE-2020-37163
QuickDate Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user credentials, database name, and system version.

CVE-2020-37218
com_hdwplayer Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter to extract sensitive database information from the hdwplayer_videos table.

CVE-2020-37242
Ultimate Maps Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information.

CVE-2020-36946
SyncBreeze DevOps
8.7
HIGH
EPSS
0.2%
2020 CWE-770 1 PoC

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.

CVE-2020-37068
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-37146
Aptina AR0130 960P 1.3MP Camera General
8.7
HIGH
EPSS
0.0%
2020 CWE-306 1 PoC

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system settings.

CVE-2020-36939
Cassandra Web Web Database
8.7
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

CVE-2020-37113
GUnet OpenEclass Web
8.7
HIGH
EPSS
0.2%
2020 CWE-434 1 PoC

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature.

CVE-2020-36850
JSS React Sample Application General
8.7
HIGH
EPSS
0.1%
2020 CWE-200 1 PoC

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.