7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36079
Software Genérico Web
N/A
UNKNOWN
EPSS
15.6%
2020 2 PoCs

Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example, place a .php file in the server's uploaded/ directory. NOTE: the vendor disputes this because exploitation can only be performed by an admin who has "lots of other possibilities to harm a site.

CVE-2020-35263
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

CVE-2020-0155
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736386

CVE-2020-18662
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVE-2020-19642
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card.

CVE-2020-23450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

CVE-2020-35736
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.4%
2020 0 PoCs

GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

CVE-2020-28950
Kaspersky Anti-Ransomware Tool General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.

CVE-2020-6835
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.

CVE-2020-15078
OpenVPN Networking
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-305 2 PoCs

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

CVE-2020-15831
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.

CVE-2020-35550
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).

CVE-2020-26943
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

CVE-2020-28861
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

CVE-2020-9390
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.

CVE-2020-14944
Software Genérico General
N/A
UNKNOWN
EPSS
11.8%
2020 2 PoCs

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

CVE-2020-10515
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

CVE-2020-26088
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.

CVE-2020-13118
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
3.7%
2020 1 PoC

An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

CVE-2020-11526
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read.