1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15255
timetracker General
8.7
HIGH
EPSS
1.2%
2020 CWE-74 2 PoCs

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

CVE-2020-37116
GUnet OpenEclass Web Database
8.7
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise.

CVE-2020-37093
Netis E1+ General
8.7
HIGH
EPSS
0.1%
2020 CWE-201 1 PoC

Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in plain text.

CVE-2020-36878
ReQuest Serious Play Media Player General
8.7
HIGH
EPSS
0.0%
2020 CWE-73 2 PoCs

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.

CVE-2020-37097
EW-7438RPn Mini General
8.7
HIGH
EPSS
0.1%
2020 CWE-522 1 PoC

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

CVE-2020-37214
Voyager General
8.7
HIGH
EPSS
0.5%
2020 CWE-22 1 PoC

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

CVE-2020-37023
Koken CMS Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVE-2020-36973
PDW File Browser Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.

CVE-2020-37146
Aptina AR0130 960P 1.3MP Camera General
8.7
HIGH
EPSS
0.0%
2020 CWE-306 1 PoC

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system settings.

CVE-2020-36964
YATinyWinFTP General
8.7
HIGH
EPSS
0.1%
2020 CWE-787 1 PoC

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVE-2020-36920
iDS6 DSSPro Digital Signage System Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

CVE-2020-36939
Cassandra Web Web Database
8.7
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

CVE-2020-4062
Conjur OSS Helm Chart DevOps
8.7
HIGH
EPSS
0.4%
2020 CWE-284 1 PoC

In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with an open port. This allows an attacker to gain full read & write access to the Conjur Postgres database, including escalating the attacker's privileges to assume full control. A malicious actor who knows the IP address and port number of the Postgres database and has access into the Kubernetes cluster where Conjur runs can gain full read & write access to the Postgres database. This enables the attacker to write a policy that allows full access to

CVE-2020-37069
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-36963
Intelbras Router RF 301K Web Networking
8.7
HIGH
EPSS
0.3%
2020 CWE-306 1 PoC

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

CVE-2020-36876
ReQuest Serious Play Pro General
8.7
HIGH
EPSS
0.1%
2020 CWE-532 2 PoCs

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.

CVE-2020-37173
AVideo Platform Web
8.7
HIGH
EPSS
0.1%
2020 CWE-359 1 PoC

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

CVE-2020-37088
School ERP Pro Web
8.7
HIGH
EPSS
2.2%
2020 CWE-22 1 PoC

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

CVE-2020-36850
JSS React Sample Application General
8.7
HIGH
EPSS
0.1%
2020 CWE-200 1 PoC

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.

CVE-2020-36942
CMSsite Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.