7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-23522
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

CVE-2020-28415
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28414).

CVE-2020-28270
object-hierarchy-access General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-7590
DCA Vantage Analyzer General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-259 1 PoC

A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-coded password to protect the onboard database. This could allow an attacker to read and or modify the onboard database. Successful exploitation requires direct physical access to the device.

CVE-2020-25816
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.

CVE-2020-9454
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

CVE-2020-15330
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.

CVE-2020-27623
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.

CVE-2020-15654
Firefox ESR General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived broken state, especially when interactions with existing browser dialogs and warnings do not work. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.

CVE-2020-20988
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.

CVE-2020-21224
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.1%
2020 2 PoCs

A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server

CVE-2020-8992
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.

CVE-2020-6478
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-27631
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.

CVE-2020-35677
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. The caveat here is that an attacker would need administrative privileges in order to create the payload. One might think this completely mitigates the privilege-escalation impact as there is only one high-privileged role. However, it was discovered that the endpoint responsible for creating the group lacks CSRF protection.

CVE-2020-0416
Android General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-155288585

CVE-2020-35737
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2020 2 PoCs

In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information by manipulating the unvalidated UserIndex parameter, aka Insecure Direct Object Reference.

CVE-2020-25449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 3 PoCs

Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.

CVE-2020-19001
Software Genérico General
N/A
UNKNOWN
EPSS
7.5%
2020 2 PoCs

Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.