7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-24577
Software Genérico General
N/A
UNKNOWN
EPSS
16.8%
2020 3 PoCs

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the application's response body for a /tmp/var/passwd or /tmp/home/wan_stat URI.

CVE-2020-5811
Umbraco CMS Web
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and expected paths when installing an Umbraco package.

CVE-2020-13401
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
12.9%
2020 1 PoC

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

CVE-2020-0910
Windows Windows
N/A
UNKNOWN
EPSS
14.8%
2020 2 PoCs

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.

CVE-2020-15817
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

CVE-2020-6519
Chrome General
N/A
UNKNOWN
EPSS
23.7%
2020 2 PoCs

Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVE-2020-14370
podman DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-212 1 PoC

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVE-2020-13431
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.

CVE-2020-25409
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.

CVE-2020-5142
SonicOS Web Networking
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in the firewall SSLVPN portal. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.

CVE-2020-20094
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages

CVE-2020-36002
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.

CVE-2020-27600
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
62.3%
2020 1 PoC

HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via shell metacharacters in the ssid0 or ssid1 parameter.

CVE-2020-29664
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.

CVE-2020-16157
Software Genérico Web
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.

CVE-2020-8674
Intel(R) AMT and Intel(R) ISM General
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-27842
openjpeg General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-125 2 PoCs

There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

CVE-2020-9335
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.

CVE-2020-15327
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.