1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-28433
node-latex-pdf General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package node-latex-pdf.

CVE-2020-1773
((OTRS)) Community Edition General
7.3
HIGH
EPSS
0.5%
2020 CWE-331 1 PoC

An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

CVE-2020-14724
Solaris Operating System Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:

CVE-2020-28499
merge General
7.3
HIGH
EPSS
0.5%
2020 2 PoCs

All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .

CVE-2020-36541
Demokratian Web Database
7.3
HIGH
EPSS
0.3%
2020 CWE-89 3 PoCs

A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown functionality of the file basicos_php/genera_select.php. The manipulation of the argument id_provincia with the input -1%20union%20all%20select%201,2,3,4,database() leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2020-28459
markdown-it-decorate Web
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

CVE-2020-13285
GitLab DevOps Web
7.3
HIGH
EPSS
0.1%
2020 1 PoC

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

CVE-2020-7351
Trixbox Community Edition Web
7.3
HIGH
EPSS
68.9%
2020 CWE-78 1 PoC

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.

CVE-2020-7260
Mcafee Application and Change Control (MACC) General
7.3
HIGH
EPSS
0.1%
2020 CWE-264 1 PoC

DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

CVE-2020-16984
Azure Sphere Cloud
7.3
HIGH
EPSS
0.2%
2020 1 PoC

Azure Sphere Unsigned Code Execution Vulnerability

CVE-2020-12525
fdtCONTAINER Component DevOps
7.3
HIGH
EPSS
0.1%
2020 CWE-502 1 PoC

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

CVE-2020-7737
safetydance General
7.3
HIGH
EPSS
0.4%
2020 2 PoCs

All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

CVE-2020-28495
total.js General
7.3
HIGH
EPSS
6.1%
2020 1 PoC

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

CVE-2020-28458
datatables.net Web
7.3
HIGH
EPSS
1.2%
2020 2 PoCs

All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

CVE-2020-2785
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d

CVE-2020-28436
google-cloudstorage-commands Cloud
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package google-cloudstorage-commands.

CVE-2020-36542
Demokratian Web
7.3
HIGH
EPSS
0.5%
2020 CWE-269 3 PoCs

A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2020-12028
FactoryTalk View SE Web
7.3
HIGH
EPSS
29.9%
2020 CWE-264 1 PoC

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

CVE-2020-12510
TwinCat XAR 3.1 General
7.3
HIGH
EPSS
0.2%
2020 CWE-276 1 PoC

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher pr