7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12102
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).

CVE-2020-27691
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

CVE-2020-14303
Samba General
N/A
UNKNOWN
EPSS
26.4%
2020 1 PoC

A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.

CVE-2020-26960
Firefox General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVE-2020-36478
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

CVE-2020-21651
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.

CVE-2020-19626
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.

CVE-2020-9024
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.

CVE-2020-10429
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-settings.php by adding a question mark (?) followed by the payload.

CVE-2020-0240
Android General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594

CVE-2020-24115
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

CVE-2020-21681
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

CVE-2020-3976
ESXi, vCenter Server, and Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
2.5%
2020 1 PoC

VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

CVE-2020-12425
Firefox General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.

CVE-2020-14062
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.6%
2020 7 PoCs

FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).

CVE-2020-25698
moodle General
N/A
UNKNOWN
EPSS
0.7%
2020 CWE-284 1 PoC

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVE-2020-9376
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 1 PoC

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2020-21601
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.

CVE-2020-13802
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2020 2 PoCs

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

CVE-2020-8141
dot General
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-94 1 PoC

The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.