7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7602
node-prompt-here General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.

CVE-2020-29215
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.

CVE-2020-27800
upx General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-119 1 PoC

A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.

CVE-2020-24583
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2020 2 PoCs

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.

CVE-2020-5505
Software Genérico Web
N/A
UNKNOWN
EPSS
22.9%
2020 1 PoC

Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.

CVE-2020-3673
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in Agatti, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MSM8905, MSM8909W, MSM8917, MSM8940, MSM8953, MSM8996AU, Nicobar, QCA6390, QCA6574AU, QCM2150, QCS605, QM215, Rennell, SA6155P, SA8155P, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SD

CVE-2020-36485
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.

CVE-2020-12892
AMD Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.

CVE-2020-11539
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 3 PoCs

An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band doesn't have any authentication or signature verification. Thus, any attacker can control a parameter of the device.

CVE-2020-7608
yargs-parser General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

CVE-2020-28343
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung ID is SVE-2020-18610 (November 2020).

CVE-2020-28927
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.

CVE-2020-29458
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem.

CVE-2020-35609
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability.

CVE-2020-14152
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVE-2020-36333
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
46.2%
2020 1 PoC

themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database, because of a reset_wizard_actions hook.

CVE-2020-36011
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

CVE-2020-5179
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

CVE-2020-11439
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.

CVE-2020-9461
Software Genérico Web
N/A
UNKNOWN
EPSS
2.1%
2020 2 PoCs

Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.