7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15313
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.

CVE-2020-35931
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

CVE-2020-13388
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 2 PoCs

An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.

CVE-2020-0093
Android General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148705132

CVE-2020-12676
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".

CVE-2020-25830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.

CVE-2020-18713
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php

CVE-2020-26560
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey.

CVE-2020-10833
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).

CVE-2020-18127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.

CVE-2020-13971
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

In Shopware before 6.2.3, authenticated users are allowed to use the Mediabrowser fileupload feature to upload SVG images containing JavaScript. This leads to Persistent XSS. An uploaded image can be accessed without authentication.

CVE-2020-7942
Puppet General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Previously, Puppet operated on a model that a node with a valid certificate was entitled to all information in the system and that a compromised certificate allowed access to everything in the infrastructure. When a node's catalog falls back to the `default` node, the catalog can be retrieved for a different node by modifying facts for the Puppet run. This issue can be mitigated by setting `strict_hostname_checking = true` in `puppet.conf` on your Puppet master. Puppet 6.13.0 and 5.5.19 changes the default behavior for strict_hostname_checking from false to true. It is recommended that Puppet

CVE-2020-28037
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
12.7%
2020 1 PoC

is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

CVE-2020-12422
Firefox Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

CVE-2020-11629
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gained access to the CA UI could exploit this to upload malicious scripts to the server. (Risks associated with this issue alone are negligible unless a malicious user already has gained access to the CA UI through other means, as a trusted user is already trusted to upload scripts by virtue of having access to the val

CVE-2020-14321
Moodle General
N/A
UNKNOWN
EPSS
39.4%
2020 CWE-863 4 PoCs

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

CVE-2020-16306
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2020 1 PoC

A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

CVE-2020-15825
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.

CVE-2020-6433
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-5968
NVIDIA vGPU Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed by using an index or pointer, such as memory or files, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).