1631 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12510
TwinCat XAR 3.1 General
7.3
HIGH
EPSS
0.2%
2020 CWE-276 1 PoC

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher pr

CVE-2020-6293
SAP NetWeaver (Knowledge Management) General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

CVE-2020-28470
@scullyio/scully General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

CVE-2020-28461
js-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-36768
NESP2 Networking Database
7.3
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

CVE-2020-28895
Software Genérico General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVE-2020-28425
curljs General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package curljs.

CVE-2020-9392
Software Genérico Web Windows
7.3
HIGH
EPSS
1.0%
2020 1 PoC

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.

CVE-2020-28480
jointjs Web
7.3
HIGH
EPSS
0.6%
2020 4 PoCs

The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.

CVE-2020-28455
markdown-it-toc General
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

CVE-2020-28471
properties-reader General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package properties-reader before 2.2.0.

CVE-2020-7679
casperjs General
7.3
HIGH
EPSS
0.8%
2020 3 PoCs

In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

CVE-2020-14561
Hospitality Reporting and Analytics Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVS

CVE-2020-29029
GateManager Web
7.3
HIGH
EPSS
0.3%
2020 CWE-20 1 PoC

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

CVE-2020-2543
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partia

CVE-2020-7778
systeminformation General
7.3
HIGH
EPSS
1.1%
2020 1 PoC

This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

CVE-2020-28426
kill-process-on-port General
7.3
HIGH
EPSS
6.9%
2020 1 PoC

All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

CVE-2020-7795
get-npm-package-version General
7.3
HIGH
EPSS
4.3%
2020 1 PoC

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

CVE-2020-28429
geojson2kml General ⚡ nuclei
7.3
HIGH
EPSS
84.8%
2020 1 PoC

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

CVE-2020-2787
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d