94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-21016
Software Genérico Web
9.8
CRITICAL
EPSS
10.4%
2020 2 PoCs

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.

CVE-2020-5902
🔥 KEV BIG-IP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2020 63 PoCs

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

CVE-2020-6091
Epson Web
9.8
CRITICAL
EPSS
0.4%
2020 CWE-288 1 PoC

An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A specially crafted series of HTTP requests can cause authentication bypass resulting in information disclosure. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2020-36708
Antreas Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2020 CWE-94 2 PoCs

The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4. This is due to epsilon_framework_ajax_action. This makes it possible for unauthenticated attackers to call functions and achieve remote code execution.

CVE-2020-11101
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2020 1 PoC

Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

CVE-2020-7708
irrelon-path General
9.8
CRITICAL
EPSS
1.1%
2020 3 PoCs

The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

CVE-2020-29168
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2020 1 PoC

SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

CVE-2020-10181
🔥 KEV Software Genérico Networking
9.8
CRITICAL
EPSS
20.6%
2020 2 PoCs

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.

CVE-2020-3248
Cisco UCS Director Web Networking
9.8
CRITICAL
EPSS
46.1%
2020 CWE-20 1 PoC

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-24600
Software Genérico Database
9.8
CRITICAL
EPSS
0.2%
2020 2 PoCs

Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

CVE-2020-14841
WebLogic Server Database
9.8
CRITICAL
EPSS
13.5%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-13927
🔥 KEV Apache Airflow Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2020 3 PoCs

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.m

CVE-2020-2733
JD Edwards EnterpriseOne Tools Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
88.9%
2020 2 PoCs

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-28440
corenlp-js-interface General
9.8
CRITICAL
EPSS
4.1%
2020 1 PoC

All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

CVE-2020-10827
Software Genérico Web
9.8
CRITICAL
EPSS
13.4%
2020 2 PoCs

A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVE-2020-7704
linux-cmdline General
9.8
CRITICAL
EPSS
1.7%
2020 2 PoCs

The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.

CVE-2016-3427
🔥 KEV Software Genérico Database
9.8
CRITICAL
EPSS
93.9%
2016 4 PoCs

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVE-2016-8735
🔥 KEV Apache Tomcat Web Database
9.8
CRITICAL
EPSS
93.9%
2016 5 PoCs

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

CVE-2016-3088
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2016 7 PoCs

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

CVE-2016-9052
Aerospike version Aerospike Database Server 3.10.0.3 General
9.8
CRITICAL
EPSS
14.8%
2016 1 PoC

An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_by_iname resulting in remote code execution. An attacker can simply connect to the port to trigger this vulnerability.