7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-6171
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.5%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVE-2020-18395
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs.

CVE-2020-8838
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.

CVE-2020-28722
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.

CVE-2020-27820
kernel General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-416 1 PoC

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

CVE-2020-7105
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

CVE-2020-35729
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2020 4 PoCs

KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

CVE-2020-28384
Solid Edge SE2020 General
N/A
UNKNOWN
EPSS
1.3%
2020 CWE-121 1 PoC

A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2020-25860
Pengutronix RAUC General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-367 1 PoC

The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.

CVE-2020-25204
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However, the application does not enforce any authorization schema on the broadcast receiver, allowing any application to send fully customizable in-game push notifications.

CVE-2020-36322
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.

CVE-2020-29364
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.

CVE-2020-9451
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet created) log file to anti_ransomware_service.exe. On reboot, this forces the anti_ransomware_service to try to write its log into its own process, crashing in a SHARING VIOLATION. This crash occurs on every reboot.

CVE-2020-27467
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.3%
2020 0 PoCs

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

CVE-2020-11604
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an Out-of-bounds read in the MLDAP Trustlet. The Samsung ID is SVE-2019-16565 (April 2020).

CVE-2020-22038
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.

CVE-2020-12666
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.

CVE-2020-23856
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

CVE-2020-12987
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

CVE-2020-20236
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.