7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-21680
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

CVE-2020-13949
Apache Thrift Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

CVE-2020-11511
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.8%
2020 2 PoCs

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.

CVE-2020-21784
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.

CVE-2020-8279
Nextcloud Social Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-295 1 PoC

Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.

CVE-2020-28874
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

CVE-2020-29260
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

CVE-2020-12608
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2020 3 PoCs

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

CVE-2020-9030
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.

CVE-2020-29540
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

API calls in the Translation API feature in Systran Pure Neural Server before 9.7.0 allow a threat actor to use the Systran Pure Neural Server as a Denial-of-Service proxy by sending a large amount of translation requests to a destination host on any given TCP port regardless of whether a web service is running on the destination port.

CVE-2020-14157
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

The wireless-communication feature of the ABUS Secvest FUBE50001 device does not encrypt sensitive data such as PIN codes or IDs of used proximity chip keys (RFID tokens). This makes it easier for an attacker to disarm the wireless alarm system.

CVE-2020-21998
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.4%
2020 1 PoC

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

CVE-2020-11515
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2020 0 PoCs

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).

CVE-2020-35416
Software Genérico Web
N/A
UNKNOWN
EPSS
4.5%
2020 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

CVE-2020-28382
Solid Edge SE2020 General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-787 1 PoC

A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in a out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2020-24223
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.3%
2020 3 PoCs

Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.

CVE-2020-13977
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.

CVE-2020-26200
Kaspersky Rescue Disk Version General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.

CVE-2020-13831
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020).

CVE-2020-10787
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).