7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-6206
SAP Cloud Platform Integration for Data Services Cloud
4.7
MEDIUM
EPSS
0.2%
2020 1 PoC

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

CVE-2020-14659
CRM Technical Foundation Web Database
4.7
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update

CVE-2020-7318
ePolicy Orchistrator (ePO) Web ⚡ nuclei
4.6
MEDIUM
EPSS
12.5%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

CVE-2020-37175
P2PWIFICAM2 for iOS General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the Camera ID input field. Attackers can paste a 257-character buffer into the Camera ID field to trigger an application crash on iOS devices.

CVE-2020-37208
Nsauditor SpotFTP FTP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-787 1 PoC

SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

CVE-2020-37207
Nsauditor SpotDialup General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37211
Nsauditor SpotIM General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37180
Nsauditor GTalk Password Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37206
Nsauditor ShareAlarmPro Advanced Network Access Control General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field.

CVE-2020-37200
Nsauditor NetShareWatcher General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an application crash.

CVE-2020-1771
((OTRS)) Community Edition Web
4.6
MEDIUM
EPSS
0.6%
2020 CWE-79 2 PoCs

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVE-2020-37188
Nsauditor SpotOutlook General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.

CVE-2020-37194
Nsauditor Backup Key Recovery Recover Keys Crashed Hard Disk Drive General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an application crash.

CVE-2020-7300
DLP ePO extension Web
4.6
MEDIUM
EPSS
0.1%
2020 CWE-863 1 PoC

Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.

CVE-2020-37189
TaskCanvas General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash.

CVE-2020-37134
UltraVNC Viewer General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.

CVE-2020-37178
KeePass Password Safe General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-94 2 PoCs

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.

CVE-2020-37196
Nsauditor Dnss Domain Name Search Software General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-37179
Nsauditor APKF Product Key Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37197
Nsauditor Dnss Domain Name Search Software General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.