7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-5665
MELSEC iQ-F series FX5U(C) CPU unit General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.

CVE-2020-27413
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.

CVE-2020-28016
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Exim 4 before 4.94.2 allows an off-by-two Out-of-bounds Write because "-F ''" is mishandled by parse_fix_phrase.

CVE-2020-7982
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).

CVE-2020-25409
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.

CVE-2020-16154
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

CVE-2020-8265
Node General
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-416 1 PoC

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

CVE-2020-13833
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).

CVE-2020-14375
dpdk General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-367 1 PoC

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-7604
pulverizr General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.

CVE-2020-27844
openjpeg General
N/A
UNKNOWN
EPSS
2.0%
2020 CWE-20 3 PoCs

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-17527
Apache Tomcat Web
N/A
UNKNOWN
EPSS
10.5%
2020 CWE-200 5 PoCs

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

CVE-2020-24861
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

CVE-2020-28071
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.

CVE-2020-12624
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

CVE-2020-29651
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

CVE-2020-5192
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
41.7%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

CVE-2020-25752
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the MD5 hash of the username and serial number mixed with some static strings. The serial number can be retrieved by an unauthenticated user at /info.xml. These passwords can be easily calculated by an attacker; users are unable to change these passwords.

CVE-2020-8287
Node Web
N/A
UNKNOWN
EPSS
11.9%
2020 CWE-444 2 PoCs

Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

CVE-2020-27361
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 0 PoCs

An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.