7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-27558
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.

CVE-2020-6564
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

CVE-2020-10477
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.

CVE-2020-9060
ZEN25 General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-346 1 PoC

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A version 3.95, and Fibaro FGWPB-111 version 4.3, are susceptible to denial of service and resource exhaustion via malformed SECURITY NONCE GET, SECURITY NONCE GET 2, NO OPERATION, or NIF REQUEST messages.

CVE-2020-25267
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.

CVE-2020-25566
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this request and can reset any user’s password by changing the username to that user and password to base64(desired password).

CVE-2020-8544
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows SSRF.

CVE-2020-24622
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

CVE-2020-15920
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 4 PoCs

There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.

CVE-2020-12967
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2020-7934
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2020 5 PoCs

In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.

CVE-2020-27402
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.

CVE-2020-5665
MELSEC iQ-F series FX5U(C) CPU unit General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.

CVE-2020-27413
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.

CVE-2020-28016
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.

CVE-2020-16154
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

CVE-2020-8265
Node General
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-416 1 PoC

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVE-2020-13833
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).

CVE-2020-14375
dpdk General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-367 1 PoC

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.