7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-11710
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 1 PoC

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user de

CVE-2020-35572
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 1 PoC

Adminer through 4.7.8 allows XSS via the history parameter to the default URI.

CVE-2020-28188
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2020 3 PoCs

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

CVE-2020-5764
MX Player Android App General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of "FILE_LIST" with a "name" field containing directory traversal characters (../). This will result in the file being transferred to the victim's phone, but being saved outside of the intended "/sdcard/MXshare" directory. In some instances, an attacker can achieve remote code execution by writing ".odex" and ".vdex" files

CVE-2020-15473
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

CVE-2020-12862
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

CVE-2020-15533
Software Genérico Database
N/A
UNKNOWN
EPSS
11.4%
2020 1 PoC

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

CVE-2020-12798
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.

CVE-2020-15806
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

CVE-2020-5751
TCExam Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.

CVE-2020-8240
Pulse Secure Desktop Client Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

CVE-2020-7014
Elasticsearch Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-266 1 PoC

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication tokens. An attacker who is able to generate an API key and an authentication token can perform a series of steps that result in an authentication token being generated with elevated privileges.

CVE-2020-15321
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

CVE-2020-13432
Software Genérico Web
N/A
UNKNOWN
EPSS
7.4%
2020 5 PoCs

rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.

CVE-2020-11200
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Buffer over-read while parsing RPS due to lack of check of input validation on values received from user side. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-12954
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-693 1 PoC

A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.

CVE-2020-15956
Software Genérico General
N/A
UNKNOWN
EPSS
46.5%
2020 2 PoCs

ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.

CVE-2020-25593
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.

CVE-2020-11228
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Part of RPM region was not protected from xblSec itself due to improper policy and leads to unprivileged access in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2020-23982
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'