7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15690
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2020 3 PoCs

In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

CVE-2020-0241
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151456667

CVE-2020-1301
Windows Windows
N/A
UNKNOWN
EPSS
59.5%
2020 2 PoCs

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.

CVE-2020-2322
Jenkins Chaos Monkey Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

CVE-2020-17449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PHP-Fusion 9.03 allows XSS via the error_log file.

CVE-2020-27518
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.

CVE-2020-3610
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Possibility of double free of the drawobj that is added to the drawqueue array of the context during IOCTL commands as there is no refcount taken for this object in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670,

CVE-2020-12683
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Katyshop2 before 2.12 has multiple stored XSS issues.

CVE-2020-11865
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

CVE-2020-25343
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php

CVE-2020-24586
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

CVE-2020-27184
NPort IA5000A Series with Telnet enabled General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.

CVE-2020-8165
https://github.com/rails/rails Web Database
N/A
UNKNOWN
EPSS
90.1%
2020 CWE-502 8 PoCs

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

CVE-2020-13168
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

CVE-2020-0242
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151643722

CVE-2020-6431
Chrome General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-5306
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.

CVE-2020-0392
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-150226608

CVE-2020-27374
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

CVE-2020-26575
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 2 PoCs

In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.