7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-1755
Moodle General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-345 1 PoC

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVE-2020-26990
JT2Go General
N/A
UNKNOWN
EPSS
1.4%
2020 CWE-843 1 PoC

A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing ASM files. A crafted ASM file could trigger a type confusion condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11897)

CVE-2020-29129
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

CVE-2020-10012
macOS General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.

CVE-2020-15890
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.

CVE-2020-23282
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.

CVE-2020-15692
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.

CVE-2020-12059
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

CVE-2020-21597
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

CVE-2020-27224
Eclipse Theia General
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-79 1 PoC

In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

CVE-2020-12717
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2020 2 PoCs

The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

CVE-2020-10875
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.

CVE-2020-19289
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.

CVE-2020-9781
iOS General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.

CVE-2020-10947
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.

CVE-2020-28935
Unbound General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-59 1 PoC

NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file was already present, they would follow symlinks if the file happened to be a symlink instead of a regular file. An additional chown of the file would then take place after it was written, making the user Unbound/NSD is supposed to run as the new owner of the file. If an attacker

CVE-2020-13159
Software Genérico General
N/A
UNKNOWN
EPSS
17.6%
2020 1 PoC

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.

CVE-2020-24088
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in MmMapIoSpace routine in Foxconn Live Update Utility 2.1.6.26, allows local attackers to escalate privileges.

CVE-2020-12837
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.