1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36920
iDS6 DSSPro Digital Signage System Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 2 PoCs

iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users to elevate privileges through console JavaScript functions. Attackers can create users, modify roles and permissions, and potentially achieve full application takeover by exploiting insecure direct object references.

CVE-2020-36850
JSS React Sample Application General
8.7
HIGH
EPSS
0.1%
2020 CWE-200 1 PoC

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.

CVE-2020-37069
FTP Utility General
8.7
HIGH
EPSS
0.2%
2020 CWE-120 1 PoC

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-15275
moin-1.9 Web
8.7
HIGH
EPSS
0.4%
2020 CWE-79 1 PoC

MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.

CVE-2020-37034
HelloWeb General
8.7
HIGH
EPSS
0.2%
2020 CWE-22 1 PoC

HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.

CVE-2020-5421
Spring Framework Web
8.7
HIGH
EPSS
63.8%
2020 7 PoCs

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVE-2020-36896
QiHang Media Web Digital Signage General
8.7
HIGH
EPSS
1.4%
2020 CWE-522 2 PoCs

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.

CVE-2020-36893
i-Media Server Digital Signage General
8.7
HIGH
EPSS
6.9%
2020 CWE-22 2 PoCs

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

CVE-2020-36964
YATinyWinFTP General
8.7
HIGH
EPSS
0.1%
2020 CWE-787 1 PoC

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVE-2020-11066
TYPO3 CMS Web
8.7
HIGH
EPSS
0.5%
2020 CWE-915 1 PoC

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering deletion of an arbitrary directory in the file system, if it is writable for the web server. It can also trigger message submission via email using the identity of the web site (mail relay). Another insecure deserialization vulnerability is required to actually exploit mentioned aspects. This has been fixed in 9.5.17 and 10

CVE-2020-36946
SyncBreeze DevOps
8.7
HIGH
EPSS
0.2%
2020 CWE-770 1 PoC

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.

CVE-2020-15227
application Web ⚡ nuclei
8.7
HIGH
EPSS
93.8%
2020 CWE-74 4 PoCs

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

CVE-2020-36872
BACnet Test Server General
8.7
HIGH
EPSS
0.3%
2020 CWE-400 2 PoCs

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails to properly validate the BVLC Length field in incoming UDP BVLC frames on the default BACnet port (47808/udp). A remote unauthenticated attacker can send a malformed BVLC Length value to trigger an access violation and crash the application, resulting in a denial of service.

CVE-2020-11026
WordPress Web Windows
8.7
HIGH
EPSS
4.4%
2020 CWE-707 1 PoC

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2020-36910
SMP-8000QD General
8.7
HIGH
EPSS
0.5%
2020 CWE-78 2 PoCs

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

CVE-2020-5232
@ensdomains/ens General
8.7
HIGH
EPSS
0.3%
2020 CWE-285 1 PoC

A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.

CVE-2020-36963
Intelbras Router RF 301K Web Networking
8.7
HIGH
EPSS
0.3%
2020 CWE-306 1 PoC

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

CVE-2020-37097
EW-7438RPn Mini General
8.7
HIGH
EPSS
0.1%
2020 CWE-522 1 PoC

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

CVE-2020-36969
M/Monit Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 1 PoC

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.

CVE-2020-36942
CMSsite Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.