7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10420
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php by adding a question mark (?) followed by the payload.

CVE-2020-8244
bl General
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-126 2 PoCs

A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.

CVE-2020-13224
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

CVE-2020-27693
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 stores administrative passwords using a hash that is considered outdated.

CVE-2020-19285
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

CVE-2020-24918
Software Genérico General
N/A
UNKNOWN
EPSS
13.0%
2020 2 PoCs

A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example. NOTE: The vendor states that the RTSP library is used for DEMO only, using it in product is a customer's behavior. Ambarella has emphasized that RTSP is DEMO only library, should NOT be used in product in our document. Because

CVE-2020-13160
Software Genérico General
N/A
UNKNOWN
EPSS
88.8%
2020 3 PoCs

AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

CVE-2020-0451
Android General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9 Android-8.0 Android-8.1Android ID: A-158762825

CVE-2020-21531
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

CVE-2020-23478
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.

CVE-2020-16291
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-20139
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

CVE-2020-8654
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2020 2 PoCs

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

CVE-2020-11441
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2020 0 PoCs

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

CVE-2020-16170
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.

CVE-2020-10228
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

CVE-2020-11700
Software Genérico Web
N/A
UNKNOWN
EPSS
14.0%
2020 2 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

CVE-2020-10366
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.

CVE-2020-18659
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php

CVE-2020-28906
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.