7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-26105
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

CVE-2020-36154
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.

CVE-2020-8145
UniFi Video Controller (for Windows 7/8/10 x64) Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.

CVE-2020-19038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

File Deletion vulnerability in Halo 0.4.3 via delBackup.

CVE-2020-12750
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via SPEN. The Samsung ID is SVE-2020-17019 (May 2020).

CVE-2020-25040
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.

CVE-2020-10848
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos 9810 chipsets) software. Arbitrary memory mapping exists in TEE. The Samsung ID is SVE-2019-16665 (February 2020).

CVE-2020-5839
Symantec Endpoint Detection And Response General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Symantec Endpoint Detection And Response, prior to 4.4, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

CVE-2020-36557
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.

CVE-2020-28903
Software Genérico Web
N/A
UNKNOWN
EPSS
26.3%
2020 2 PoCs

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.

CVE-2020-12911
AMD Graphics Driver for Windows Web Windows
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-125 1 PoC

A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API request can cause an out-of-bounds read and denial of service (BSOD). This vulnerability can be triggered from a non-privileged account.

CVE-2020-25221
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow. This can be triggered by any 64-bit process that can use ptrace() or process_vm_readv(), aka CID-9fa2dd946743.

CVE-2020-7658
meinheld Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

meinheld prior to 1.0.2 is vulnerable to HTTP Request Smuggling. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing.

CVE-2020-14155
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVE-2020-25279
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).

CVE-2020-11857
Operation Bridge Reporter. General
N/A
UNKNOWN
EPSS
63.2%
2020 1 PoC

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user

CVE-2020-7988
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.

CVE-2020-35488
Software Genérico Windows
N/A
UNKNOWN
EPSS
19.4%
2020 1 PoC

The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.)

CVE-2020-26991
JT2Go General
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-822 1 PoC

A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11899)

CVE-2020-19724
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.