7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15537
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.

CVE-2020-23466
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.

CVE-2020-5393
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

CVE-2020-35990
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.

CVE-2020-14293
Software Genérico General
N/A
UNKNOWN
EPSS
28.8%
2020 4 PoCs

conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).

CVE-2020-18724
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS attack while opening a contact list.

CVE-2020-9426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

OX Guard 2.10.3 and earlier allows XSS.

CVE-2020-22159
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.

CVE-2020-7373
Software Genérico DevOps
N/A
UNKNOWN
EPSS
90.3%
2020 2 PoCs

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.

CVE-2020-28042
Software Genérico General
N/A
UNKNOWN
EPSS
36.0%
2020 1 PoC

ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.

CVE-2020-15949
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

CVE-2020-11122
Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'Null Pointer exception while playing crafted mkv file as data stream get deleted on secondary invalid configuration' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in APQ8098, Bitra, Kamorta, SA6155P, Saipan, SM6150, SM7150, SM8150, SM8250, SXR2130

CVE-2020-5783
IgniteNet HeliOS GLinq Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.

CVE-2020-23829
Software Genérico Web
N/A
UNKNOWN
EPSS
2.5%
2020 1 PoC

interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.

CVE-2020-28942
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue exists in PrimeKey EJBCA before 7.4.3 when enrolling with EST while proxied through an RA over the Peers protocol. As a part of EJBCA's domain security model, the peer connector allows the restriction of client certificates (for the RA, not the end user) to a limited set of allowed CAs, thus restricting the accessibility of that RA to the rights it has within a specific role. While this works for other protocols such as CMP, it was found that the EJBCA enrollment over an EST implementation bypasses this check, allowing enrollment with a valid client certificate through any functioning

CVE-2020-36287
Jira Server General
N/A
UNKNOWN
EPSS
62.7%
2020 CWE-863 2 PoCs

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check.

CVE-2020-25789
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.

CVE-2020-13452
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

CVE-2020-7471
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.4%
2020 6 PoCs

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

CVE-2020-12851
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 3 PoCs

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted files will be placed in the targeted user folders.