7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-8950
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.0%
2020 2 PoCs

The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary folder with an arbitrary file name.

CVE-2020-12802
LibreOffice General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-200 1 PoC

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

CVE-2020-5971
NVIDIA vGPU Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-11602
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).

CVE-2020-15916
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2020 2 PoCs

goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.

CVE-2020-25367
Software Genérico General
N/A
UNKNOWN
EPSS
24.0%
2020 1 PoC

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

CVE-2020-26953
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

CVE-2020-14166
Jira Service Desk Server and Data Center Web
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.

CVE-2020-12129
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.

CVE-2020-22033
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service.

CVE-2020-12894
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.

CVE-2020-11259
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking

CVE-2020-11964
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”

CVE-2020-8255
Pulse Connect Secure / Pulse Policy Secure General
N/A
UNKNOWN
EPSS
13.5%
2020 CWE-20 1 PoC

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.

CVE-2020-9031
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.

CVE-2020-25987
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

CVE-2020-5191
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

CVE-2020-5769
Teltonika Gateway TRB245 Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.02 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by injecting malicious client-side code into the 'URL/ Host / Connection' form in the 'DATA TO SERVER' configuration section.

CVE-2020-6956
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp.

CVE-2020-35229
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The authentication token required to execute NSDP write requests on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices is not properly invalidated and can be reused until a new token is generated, which allows attackers (with access to network traffic) to effectively gain administrative privileges.