7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13813
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.

CVE-2020-20951
Software Genérico General
N/A
UNKNOWN
EPSS
7.2%
2020 1 PoC

In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

CVE-2020-8256
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
3.9%
2020 CWE-611 3 PoCs

A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

CVE-2020-29551
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 3 PoCs

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php, _internal/pc/wake.php, _internal/error_u201409.txt, _internal/runcmd.php, _internal/getConfiguration.php, ews/autoload.php, ews/del.php, ews/mod.php, ews/sync.php, utils/backup/backup_server.php, utils/backup/restore_server.php, MyScreens/timeline.config, kreator.html5/test.php, and addedlogs.txt.

CVE-2020-13850
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Artica Pandora FMS 7.44 has inadequate access controls on a web folder.

CVE-2020-2159
Jenkins CryptoMove Plugin DevOps
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.

CVE-2020-5739
Grandstream GXP1600 Series Networking
N/A
UNKNOWN
EPSS
2.5%
2020 CWE-94 1 PoC

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.

CVE-2020-15680
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

CVE-2020-12866
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

CVE-2020-9477
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capture packets at the time of authentication and gain access to the cleartext password. An attacker could use this access to create a new user account or control the device.

CVE-2020-36763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom parameters when adding or editing a post.

CVE-2020-28381
Solid Edge SE2020 General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-787 1 PoC

A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into uninitialized memory. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2020-12282
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

iSmartgate PRO 1.5.9 is vulnerable to CSRF via the busca parameter in the form used for searching for users, accessible via /index.php. (This can be combined with reflected XSS.)

CVE-2020-13416
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.

CVE-2020-12825
Software Genérico General
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.

CVE-2020-27515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.

CVE-2020-19287
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.

CVE-2020-6950
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
51.7%
2020 3 PoCs

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

CVE-2020-25267
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.

CVE-2020-7588
Opcenter Execution Discrete Windows
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-20 1 PoC

A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS (All versions < V2.6), SIMATIC IT Production Suite (All versions < V8.0), SIMATIC Notifier Server for Windows (All versions), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V1