7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-0401
Android General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150857253

CVE-2020-15780
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 6 PoCs

An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.

CVE-2020-21987
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session.

CVE-2020-11930
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.

CVE-2020-16145
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.

CVE-2020-29390
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.6%
2020 0 PoCs

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

CVE-2020-11975
Apache Unomi Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2020 0 PoCs

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

CVE-2020-27375
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.

CVE-2020-10489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.

CVE-2020-8180
Nextcloud Talk Cloud
N/A
UNKNOWN
EPSS
0.7%
2020 CWE-94 1 PoC

A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.

CVE-2020-10206
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows local attackers to view and interact with the video output of the device.

CVE-2020-15667
Firefox General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

CVE-2020-10408
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-subscriber.php by adding a question mark (?) followed by the payload.

CVE-2020-26989
JT2Go General
N/A
UNKNOWN
EPSS
1.8%
2020 CWE-121 1 PoC

A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing of PAR files. This could result in a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11892)

CVE-2020-11994
Apache Camel Web
N/A
UNKNOWN
EPSS
2.0%
2020 3 PoCs

Server-Side Template Injection and arbitrary file disclosure on Camel templating components

CVE-2020-10483
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

CVE-2020-7642
lazysizes Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.

CVE-2020-26143
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

CVE-2020-36489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename information.