7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12429
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.

CVE-2020-25563
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature and not having a JSESSIONID.

CVE-2020-12593
Symantec Endpoint Detection & Response (SEDR) General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Symantec Endpoint Detection & Response, prior to 4.5, may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.

CVE-2020-25056
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with Q(10.0) (Galaxy S20) software. Because HAL improperly checks versions, bootloading by the S.LSI NFC chipset is mishandled. The Samsung ID is SVE-2020-16169 (August 2020).

CVE-2020-19463
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow.

CVE-2020-11668
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

CVE-2020-35511
pngcheck General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-126 1 PoC

A global buffer overflow was discovered in pngcheck function in pngcheck-2.4.0(5 patches applied) via a crafted png file.

CVE-2020-27387
Software Genérico Web
N/A
UNKNOWN
EPSS
70.3%
2020 3 PoCs

An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

CVE-2020-27373
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to Plain text command over BLE.

CVE-2020-27666
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

CVE-2020-8162
https://github.com/rails/rails Web Cloud
N/A
UNKNOWN
EPSS
1.5%
2020 CWE-602 1 PoC

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVE-2020-0692
Microsoft Exchange Server 2013 Windows
N/A
UNKNOWN
EPSS
5.5%
2020 1 PoC

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

CVE-2020-5964
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

CVE-2020-13226
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

CVE-2020-10855
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

CVE-2020-5408
Spring Security Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-329 3 PoCs

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

CVE-2020-28273
set-in General
N/A
UNKNOWN
EPSS
3.9%
2020 2 PoCs

Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-8158
typeorm Database
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-471 1 PoC

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

CVE-2020-12625
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.