7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-6445
Chrome General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVE-2020-9472
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

CVE-2020-14008
Software Genérico General
N/A
UNKNOWN
EPSS
46.2%
2020 3 PoCs

Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.

CVE-2020-15600
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.

CVE-2020-11941
Software Genérico General
N/A
UNKNOWN
EPSS
4.0%
2020 2 PoCs

An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

CVE-2020-27185
NPort IA5000A Series with Moxa Service enabled General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

CVE-2020-19664
Software Genérico General
N/A
UNKNOWN
EPSS
15.2%
2020 1 PoC

DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

CVE-2020-13225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.

CVE-2020-10973
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
24.8%
2020 0 PoCs

An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

CVE-2020-14064
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

CVE-2020-24977
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 4 PoCs

GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.

CVE-2020-20138
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.

CVE-2020-22165
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
36.6%
2020 0 PoCs

PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

CVE-2020-13417
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

CVE-2020-7627
node-key-sender General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.

CVE-2020-35608
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

CVE-2020-5305
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.

CVE-2020-8497
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
22.4%
2020 0 PoCs

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and timestamps.

CVE-2020-25928
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2020 2 PoCs

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.

CVE-2020-29045
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
35.2%
2020 1 PoC

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.