7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10935
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.

CVE-2020-14473
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.

CVE-2020-17523
Apache Shiro Web
N/A
UNKNOWN
EPSS
88.8%
2020 1 PoC

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVE-2020-22158
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

CVE-2020-29654
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

CVE-2020-8819
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

CVE-2020-5530
Easy Property Listings Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2020-25967
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.

CVE-2020-11189
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-15719
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

CVE-2020-11141
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap configuration request received from peer device.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, SA415M, SA515M, SC8180X, SDX55, SM8250

CVE-2020-15797
DCA Vantage Analyzer General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-269 1 PoC

A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment (“kiosk mode”) and access the underlying operating system. Successful exploitation requires direct physical access to the system.

CVE-2020-28928
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).

CVE-2020-0883
Windows Windows
N/A
UNKNOWN
EPSS
53.0%
2020 3 PoCs

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.

CVE-2020-26971
Firefox General
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVE-2020-25201
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

CVE-2020-36230
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.5%
2020 3 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element, resulting in denial of service.

CVE-2020-9287
Fortinet FortiClient EMS Networking
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

CVE-2020-8135
uppy General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-918 2 PoCs

The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.

CVE-2020-7628
install-package General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.