7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-1766
((OTRS)) Community Edition Web
2.0
LOW
EPSS
0.6%
2020 CWE-79 1 PoC

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

CVE-2020-27351
python-apt General
2.0
LOW
EPSS
0.1%
2020 CWE-772 1 PoC

Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170. This issue affects: python-apt 1.1.0~beta1 versions prior to 1.1.0~beta1ubuntu0.16.04.10; 1.6.5ubuntu0 versions prior to 1.6.5ubuntu0.4; 2.0.0ubuntu0 versions prior to 2.0.0ubuntu0.20.04.2; 2.1.3ubuntu1 versions prior to 2.1.3ubuntu1.1;

CVE-2020-14770
Hyperion BI+ Database
2.0
LOW
EPSS
0.2%
2020 1 PoC

Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Hyperion BI+ accessible data. CVSS 3.1 Base Score 2.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I

CVE-2020-14541
Hyperion Financial Close Management Web Database
2.0
LOW
EPSS
0.2%
2020 1 PoC

Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Close Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Close Management accessible data. CVSS 3.1 Base Score 2.0 (Integrity impact

CVE-2020-1032
Windows Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.

CVE-2020-36553
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.

CVE-2020-11218
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Denial of service in baseband when NW configures LTE betaOffset-RI-Index due to lack of data validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-19320
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.

CVE-2020-29287
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.5%
2020 2 PoCs

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

CVE-2020-22210
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
43.9%
2020 0 PoCs

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-28901
Software Genérico Web
N/A
UNKNOWN
EPSS
5.5%
2020 2 PoCs

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

CVE-2020-13480
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.

CVE-2020-7610
bson General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVE-2020-3843
iOS-1 General
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4.7, watchOS 5.3.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2020-28926
Software Genérico Web
N/A
UNKNOWN
EPSS
66.1%
2020 2 PoCs

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.

CVE-2020-14008
Software Genérico General
N/A
UNKNOWN
EPSS
46.2%
2020 3 PoCs

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

CVE-2020-9472
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

CVE-2020-13828
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.

CVE-2020-0138
Android General
N/A
UNKNOWN
EPSS
5.5%
2020 1 PoC

In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416

CVE-2020-14022
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an executable or .bat file that can be executed with the help of a functionality (E.g. the "Application Starter" module) within the application.