1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37057
Online-Exam-System Database
8.8
HIGH
EPSS
0.0%
2020 CWE-89 1 PoC

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

CVE-2020-6156
Pixar General
8.8
HIGH
EPSS
0.2%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file in an instance USDC file format path element token index.

CVE-2020-12502
P+F Comtrol RocketLinx General
8.8
HIGH
EPSS
0.7%
2020 CWE-352 5 PoCs

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

CVE-2020-28600
Openscad General
8.8
HIGH
EPSS
0.7%
2020 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-6155
Pixar General
8.8
HIGH
EPSS
1.5%
2020 CWE-122 1 PoC

A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD files. A specially crafted malformed file can trigger a heap overflow, which can result in remote code execution. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.

CVE-2020-6074
Nitro Pro General
8.8
HIGH
EPSS
0.4%
2020 1 PoC

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-37151
phpMyChat Plus Web Database
8.8
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by crafting malicious payloads in the username field.

CVE-2020-35789
Software Genérico Cloud
8.8
HIGH
EPSS
0.8%
2020 1 PoC

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

CVE-2020-36945
WebDamn User Registration & Login System with User Panel Database
8.8
HIGH
EPSS
0.4%
2020 CWE-89 1 PoC

WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel.

CVE-2020-13544
Softmaker General
8.8
HIGH
EPSS
0.2%
2020 CWE-194 1 PoC

An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.

CVE-2020-6116
Nitro Pro General
8.8
HIGH
EPSS
0.3%
2020 CWE-680 1 PoC

An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed colorspace, the application can miscalculate the size of a buffer when allocating space for its colors. When using this allocated buffer, the application can write outside its bounds and cause memory corruption which can lead to code execution. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

CVE-2020-36655
Software Genérico Web
8.8
HIGH
EPSS
4.2%
2020 1 PoC

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

CVE-2020-4436
Aspera Faspex On Demand General
8.8
HIGH
EPSS
0.4%
2020 1 PoC

Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.

CVE-2020-12519
AXC F 1152 (1151412) General
8.8
HIGH
EPSS
0.2%
2020 CWE-269 1 PoC

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.

CVE-2020-36920
iDS6 DSSPro Digital Signage System Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

CVE-2020-37068
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-36964
YATinyWinFTP General
8.7
HIGH
EPSS
0.1%
2020 CWE-787 1 PoC

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVE-2020-11026
WordPress Web Windows
8.7
HIGH
EPSS
4.4%
2020 CWE-707 1 PoC

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2020-15255
timetracker General
8.7
HIGH
EPSS
1.2%
2020 CWE-74 2 PoCs

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

CVE-2020-36942
CMSsite Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.