7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13825
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode parameter.

CVE-2020-25955
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.

CVE-2020-8263
Pulse Connect Secure / Pulse Policy Secure Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-79 1 PoC

A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.

CVE-2020-14294
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 4 PoCs

An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.

CVE-2020-13468
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).

CVE-2020-3665
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A possible buffer overflow would occur while processing command from firmware due to the group_id obtained from the firmware being out of range in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8909W, MSM8996, MSM8996AU, QCA6174A, QCA9377, QCA9379, SDM439, SDM636, SDM660, SDX20, SDX24, SM8150

CVE-2020-27181
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or decrypt server-side configuration files.

CVE-2020-35476
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2020 3 PoCs

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

CVE-2020-14378
dpdk General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-191 1 PoC

An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.

CVE-2020-3811
netqmail General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

CVE-2020-14447
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.

CVE-2020-5750
TCExam Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-15860
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2020 2 PoCs

Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.

CVE-2020-7913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

CVE-2020-29156
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
13.1%
2020 1 PoC

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

CVE-2020-5966
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.

CVE-2020-13786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

CVE-2020-26104
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).

CVE-2020-12838
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.