418 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-2931
Knowledge Web Database
9.8
CRITICAL
EPSS
1.9%
2020 1 PoC

Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Web Applications - InfoCenter). Supported versions that are affected are 8.6.0-8.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks of this vulnerability can result in takeover of Oracle Knowledge. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-29574
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
12.0%
2020 1 PoC

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CVE-2020-36705
Adning Advertising Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
89.5%
2020 CWE-434 1 PoC

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2020-7702
Templ8 General
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

CVE-2020-11651
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.2%
2020 14 PoCs

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.

CVE-2020-23584
Software Genérico General
9.8
CRITICAL
EPSS
19.0%
2020 2 PoCs

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

CVE-2020-36239
Jira Data Center General
9.8
CRITICAL
EPSS
16.2%
2020 CWE-862 1 PoC

Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache RMI network service which attackers, who can connect to the service, on port 40001 and potentially 40011[0][1], could execute arbitrary code of their choice in Jira through deserialization due to a missing authentication vulnerability. While Atlassian strongly suggests restricting a

CVE-2020-15422
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When parsing the archivo parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9731.

CVE-2020-13500
Aveva Database
9.8
CRITICAL
EPSS
0.3%
2020 CWE-89 1 PoC

SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.

CVE-2020-7700
phpjs Web
9.8
CRITICAL
EPSS
0.4%
2020 2 PoCs

All versions of phpjs are vulnerable to Prototype Pollution via parse_str.

CVE-2020-6627
Software Genérico Web
9.8
CRITICAL
EPSS
14.1%
2020 3 PoCs

The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

CVE-2020-3251
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
30.7%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-35797
Software Genérico Cloud
9.8
CRITICAL
EPSS
2.6%
2020 1 PoC

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

CVE-2020-3161
🔥 KEV Cisco IP phone Web Networking
9.8
CRITICAL
EPSS
87.1%
2020 CWE-20 3 PoCs

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of proper input validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web server of a targeted device. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition.

CVE-2020-7697
mock2easy General
9.8
CRITICAL
EPSS
0.5%
2020 1 PoC

This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, error); } res.json(JSON.parse(stdout)); }, '', _data.interfaceUrl, query, _data.cookie,_data.interfaceType);

CVE-2020-36847
Simple File List Web Windows
9.8
CRITICAL
EPSS
89.3%
2020 CWE-434 2 PoCs

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVE-2020-26867
PcVue General
9.8
CRITICAL
EPSS
3.2%
2020 CWE-502 2 PoCs

ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.

CVE-2020-15435
CentOS Web Panel Web
9.8
CRITICAL
EPSS
1.4%
2020 CWE-78 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_start parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9719.

CVE-2020-10915
One Agent General
9.8
CRITICAL
EPSS
83.9%
2020 CWE-502 2 PoCs

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10401.