7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12931
AMD Radeon RX 5000 Series & PRO W5000 Series General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

CVE-2020-0981
Windows 10 Version 1909 for 32-bit Systems Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity level, leading to a sandbox escape.The update addresses the vulnerability by correcting how Windows handles token relationships, aka 'Windows Token Security Feature Bypass Vulnerability'.

CVE-2020-14955
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In Jiangmin Antivirus 16.0.13.129, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220440.

CVE-2020-11653
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There can be an assertion failure and daemon restart, which causes a performance loss.

CVE-2020-8466
Trend Micro InterScan Web Security Virtual Appliance General
N/A
UNKNOWN
EPSS
27.3%
2020 1 PoC

A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.

CVE-2020-27180
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

konzept-ix publiXone before 2020.015 allows attackers to download files by iterating over the IXCopy fileID parameter.

CVE-2020-14410
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.

CVE-2020-11603
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusion in the MLDAP Trustlet allows arbitrary code execution. The Samsung ID is SVE-2020-16599 (April 2020).

CVE-2020-26051
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

CVE-2020-15436
linux kernel General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.

CVE-2020-29607
Software Genérico Web
N/A
UNKNOWN
EPSS
76.9%
2020 6 PoCs

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

CVE-2020-0797
Windows Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.

CVE-2020-21480
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2020-28383
JT2Go General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-787 2 PoCs

A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing PAR files. This can result in an out of bounds write past the memory location that is a read only image address. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11885)

CVE-2020-23980
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

CVE-2020-19363
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
5.6%
2020 0 PoCs

Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.

CVE-2020-23915
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffer over-read.

CVE-2020-11139
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-24194
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.

CVE-2020-13388
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 2 PoCs

An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.