94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37135
AMSS++ General
9.3
CRITICAL
EPSS
0.0%
2020 CWE-798 1 PoC

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

CVE-2020-13537
Moxa General
9.3
CRITICAL
EPSS
0.0%
2020 CWE-276 1 PoC

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality and among them the mosquitto executable is also run.

CVE-2020-37092
Netis E1+ General
9.3
CRITICAL
EPSS
0.1%
2020 CWE-798 1 PoC

Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.

CVE-2020-15708
libvirt General
9.3
CRITICAL
EPSS
0.2%
2020 CWE-732 1 PoC

Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.

CVE-2020-13541
Win-911 General
9.3
CRITICAL
EPSS
0.1%
2020 CWE-276 2 PoCs

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Depending on the vector chosen, an attacker can overwrite the service executable and execute arbitrary code with System privileges or replace other files within the installation folder that could lead to local privilege escalation.

CVE-2020-13534
Dream Report General
9.3
CRITICAL
EPSS
0.2%
2020 CWE-276 1 PoC

A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges which can lead to privilege escalation when used. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-36904
Selea CarPlateServer (CPS) Windows
9.3
CRITICAL
EPSS
0.1%
2020 CWE-306 2 PoCs

Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.

CVE-2020-27352
snapd DevOps
9.3
CRITICAL
EPSS
0.1%
2020 1 PoC

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may grant additional privileges to a container within the snap that were not originally intended.

CVE-2016-20049
JAD Java Decompiler General
9.3
CRITICAL
EPSS
0.1%
2016 CWE-787 1 PoC

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute shellcode in the application context.

CVE-2016-20030
ZKTeco ZKBioSecurity General
9.3
CRITICAL
EPSS
0.0%
2016 CWE-551 1 PoC

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumerate valid user accounts based on application responses.

CVE-2016-15044
Video Platform Web
9.3
CRITICAL
EPSS
67.4%
2016 CWE-502 4 PoCs

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP object in the kdata GET parameter to the redirectWidgetCmd endpoint. Successful exploitation leads to execution of arbitrary PHP code in the context of the web server process.

CVE-2016-20024
ZKTeco ZKTime.Net General
9.3
CRITICAL
EPSS
0.0%
2016 CWE-538 2 PoCs

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for privilege escalation.

CVE-2016-20052
Snews CMS upload sheller Web
9.3
CRITICAL
EPSS
0.3%
2016 CWE-434 1 PoC

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.

CVE-2016-20026
ZKTeco ZKBioSecurity Web
9.3
CRITICAL
EPSS
0.1%
2016 CWE-798 2 PoCs

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applications and execute arbitrary code with SYSTEM privileges.

CVE-2018-4048
GOG Galaxy Windows
9.3
CRITICAL
EPSS
0.1%
2018 1 PoC

An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the Desktop Galaxy Updater to exploit this vulnerability and execute arbitrary code with SYSTEM privileges.

CVE-2018-3971
Sophos General
9.3
CRITICAL
EPSS
0.0%
2018 1 PoC

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.

CVE-2018-25128
SOCA Access Control System Web Database Cloud
9.3
CRITICAL
EPSS
0.1%
2018 CWE-89 2 PoCs

SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters. Attackers can bypass authentication, retrieve password hashes, and gain administrative access with full system privileges by exploiting injection flaws in Login.php and Card_Edit_GetJson.php.

CVE-2018-25223
Crashmail General
9.3
CRITICAL
EPSS
0.4%
2018 CWE-787 1 PoC

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

CVE-2018-4005
Shimo VPN Networking
9.3
CRITICAL
EPSS
0.0%
2018 1 PoC

An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRoutingWithCommand function. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine for a successful exploit.

CVE-2018-25272
ELBA5 General
9.3
CRITICAL
EPSS
0.1%
2018 CWE-326 1 PoC

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and execute commands via the xp_cmdshell stored procedure or add backdoor users to the BEDIENER table.