7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-35228
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.

CVE-2020-12680
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Avira Free Antivirus through 15.0.2005.1866 allows local users to discover user credentials. The functions of the executable file Avira.PWM.NativeMessaging.exe are aimed at collecting credentials stored in Chrome, Firefox, Opera, and Edge. The executable does not verify the calling program and thus a request such as fetchChromePasswords or fetchCredentials will succeed. NOTE: some third parties have stated that this is "not a vulnerability.

CVE-2020-11521
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.4%
2020 1 PoC

libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

CVE-2020-12827
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.

CVE-2020-28052
Software Genérico General
N/A
UNKNOWN
EPSS
4.1%
2020 8 PoCs

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVE-2020-29000
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the RTSP service that allows a remote attacker to take full control of the device with a high-privileged account. By sending a crafted message, an attacker is able to remotely deliver a telnet session. Any attacker that has the ability to control DNS can exploit this vulnerability to remotely login to the device and gain access to the camera system.

CVE-2020-13156
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

CVE-2020-14966
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.

CVE-2020-10222
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document.

CVE-2020-26607
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileged action via a modified intent. The Samsung ID is SVE-2020-18418 (October 2020).

CVE-2020-6805
Thunderbird General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-25453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

CVE-2020-0160
Android General
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124771364

CVE-2020-11220
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2020-10111
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

CVE-2020-16211
Advantech WebAccess HMI Designer General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-125 1 PoC

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. An out-of-bounds read vulnerability may be exploited by processing specially crafted project files, which may allow an attacker to read information.

CVE-2020-6649
Fortinet FortiIsolator Networking
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID (via other, hypothetical attacks)

CVE-2020-15921
Software Genérico General
N/A
UNKNOWN
EPSS
18.4%
2020 2 PoCs

Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.

CVE-2020-8781
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.

CVE-2020-15652
Firefox Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.