7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25051
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppInfo. The Samsung ID is SVE-2020-17758 (August 2020).

CVE-2020-6010
LearnPress Wordpress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
45.5%
2020 1 PoC

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

CVE-2020-36225
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.8%
2020 4 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVE-2020-19682
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

CVE-2020-25767
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An issue was discovered in HCC Embedded NicheStack IPv4 4.1. The dnc_copy_in routine for parsing DNS domain names does not check whether a domain name compression pointer is pointing within the bounds of the packet (e.g., forward compression pointer jumps are allowed), which leads to an Out-of-bounds Read, and a Denial-of-Service as a consequence.

CVE-2020-11727
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the AlgolPlus Advanced Order Export For WooCommerce plugin 3.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the view/settings-form.php woe_post_type parameter.

CVE-2020-11474
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant.

CVE-2020-29457
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A Privilege Elevation vulnerability in OPC UA .NET Standard Stack 1.4.363.107 could allow a rogue application to establish a secure connection.

CVE-2020-6830
Firefox for iOS General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.

CVE-2020-18020
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

CVE-2020-16260
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

CVE-2020-36643
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-15929
Software Genérico General
N/A
UNKNOWN
EPSS
8.1%
2020 1 PoC

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

CVE-2020-7051
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.

CVE-2020-1903
WhatsApp for iOS General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-400 1 PoC

An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.

CVE-2020-18651
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

Buffer Overflow vulnerability in function ID3_Support::ID3v2Frame::getFrameValue in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted audio file with ID3V2 frame.

CVE-2020-27627
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.

CVE-2020-27949
macOS General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may cause unexpected changes in memory belonging to processes traced by DTrace.

CVE-2020-24029
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."

CVE-2020-9315
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.9%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.