7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-27666
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.

CVE-2020-8162
https://github.com/rails/rails Web Cloud
N/A
UNKNOWN
EPSS
1.5%
2020 CWE-602 1 PoC

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

CVE-2020-0692
Microsoft Exchange Server 2013 Windows
N/A
UNKNOWN
EPSS
5.5%
2020 1 PoC

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

CVE-2020-5964
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

CVE-2020-13226
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.

CVE-2020-10855
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

CVE-2020-5408
Spring Security Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-329 3 PoCs

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

CVE-2020-28273
set-in General
N/A
UNKNOWN
EPSS
3.9%
2020 2 PoCs

Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-8158
typeorm Database
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-471 1 PoC

Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

CVE-2020-12625
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

CVE-2020-28030
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

CVE-2020-8138
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-918 1 PoC

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

CVE-2020-24034
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2020 3 PoCs

Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie, an attacker may alter the user value inside of this cookie, and assume the role and permissions of the user specified. By assuming the role of the user internal, which is inaccessible to end users by default, the attacker gains the permissions of the internal account, which includes the ability to flash custom firmware

CVE-2020-22987
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

CVE-2020-24381
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.

CVE-2020-10396
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-language.php by adding a question mark (?) followed by the payload.

CVE-2020-35593
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

CVE-2020-27461
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2020 1 PoC

A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.

CVE-2020-35124
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the assets component of Mautic before 3.2.4 allows remote attackers to inject executable JavaScript through the Referer header of asset downloads.