7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25926
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The DNS client in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Insufficient entropy in the DNS transaction id. The impact is: DNS cache poisoning (remote). The component is: dns_query_type(). The attack vector is: a specific DNS response packet.

CVE-2020-19721
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).

CVE-2020-25644
wildfly-openssl Web
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-401 1 PoC

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-12872
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 4 PoCs

yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

CVE-2020-13652
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the login menu.

CVE-2020-12790
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.

CVE-2020-3699
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Possible out of bound access while processing assoc response from host due to improper length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, Nicobar, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QM215, SA6155P, Saipan, S

CVE-2020-10569
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938

CVE-2020-25565
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions and execute code on the server.

CVE-2020-28183
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

CVE-2020-10839
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).

CVE-2020-15302
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeover.

CVE-2020-6465
Chrome General
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-20141
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.

CVE-2020-12351
BlueZ General
N/A
UNKNOWN
EPSS
2.9%
2020 2 PoCs

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-13866
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

CVE-2020-7231
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.

CVE-2020-28908
Software Genérico General
N/A
UNKNOWN
EPSS
33.3%
2020 2 PoCs

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.