7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25990
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2020-25494
Software Genérico General
N/A
UNKNOWN
EPSS
60.7%
2020 1 PoC

Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.

CVE-2020-25507
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arbitrary code as root. During installation, the user is instructed to set the system enviroment file with world writable permissions (0777 /etc/environment). Any local unprivileged user can execute arbitrary code simply by writing to /etc/environment, which will force all users, including root, to execute arbitrary code during the next login or reboot. In addition, the entire home directory of the twcloud user at /home/twcloud is recursively given w

CVE-2020-16242
Reason S20 Ethernet Switch Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

CVE-2020-5992
NVIDIA GeForce NOW Application Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.

CVE-2020-26101
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

CVE-2020-11266
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking

CVE-2020-8463
Trend Micro InterScan Web Security Virtual Appliance General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.

CVE-2020-26100
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

CVE-2020-22044
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.

CVE-2020-15394
Software Genérico Web Database
N/A
UNKNOWN
EPSS
31.4%
2020 1 PoC

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

CVE-2020-21603
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.

CVE-2020-27197
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

TAXII libtaxii through 1.1.117, as used in EclecticIQ OpenTAXII through 0.2.0 and other products, allows SSRF via an initial http:// substring to the parse method, even when the no_network setting is used for the XML parser. NOTE: the vendor points out that the parse method "wraps the lxml library" and that this may be an issue to "raise ... to the lxml group.

CVE-2020-10946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.

CVE-2020-28898
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

In QED ResourceXpress through 4.9k, a large numeric or alphanumeric value submitted in specific URL parameters causes a server error in script execution due to insufficient input validation.

CVE-2020-7912
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

CVE-2020-35151
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

CVE-2020-3766
Adobe Genuine Integrity Service General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

CVE-2020-6577
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

CVE-2020-5744
TCExam General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.