7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12128
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.

CVE-2020-0183
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-110181479

CVE-2020-36599
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.

CVE-2020-9756
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

CVE-2020-15945
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.

CVE-2020-5739
Grandstream GXP1600 Series Networking
N/A
UNKNOWN
EPSS
2.5%
2020 CWE-94 1 PoC

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.

CVE-2020-10864
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a reboot via RPC from a Low Integrity process.

CVE-2020-27359
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.

CVE-2020-24903
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

CVE-2020-27558
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.

CVE-2020-6564
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

CVE-2020-10477
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-25566
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this request and can reset any user’s password by changing the username to that user and password to base64(desired password).

CVE-2020-8544
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows SSRF.

CVE-2020-24622
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

CVE-2020-15920
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 4 PoCs

There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

CVE-2020-12967
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2020-7934
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 5 PoCs

In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.

CVE-2020-27402
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.