7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-6797
Thunderbird General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

CVE-2020-23226
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.

CVE-2020-21483
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.

CVE-2020-35338
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.0%
2020 1 PoC

The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."

CVE-2020-6802
Mozilla Bleach Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.

CVE-2020-24584
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2020 2 PoCs

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

CVE-2020-5792
Nagios XI Web
N/A
UNKNOWN
EPSS
81.2%
2020 2 PoCs

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.

CVE-2020-25272
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.

CVE-2020-8206
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
2.0%
2020 CWE-287 1 PoC

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

CVE-2020-24949
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
90.3%
2020 2 PoCs

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

CVE-2020-10710
foreman-installer General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-522 1 PoC

A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

CVE-2020-10434
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-versions.php by adding a question mark (?) followed by the payload.

CVE-2020-21516
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

CVE-2020-13466
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.

CVE-2020-8239
Pulse Secure Desktop Cient Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

CVE-2020-25046
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

CVE-2020-18215
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.

CVE-2020-25694
postgresql Database
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-327 1 PoC

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-11436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.

CVE-2020-10128
SearchBlox Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaScript.