7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-5968
NVIDIA vGPU Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed by using an index or pointer, such as memory or files, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-15690
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2020 3 PoCs

In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

CVE-2020-25254
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnection_LocalOrLinkedServer, CreateFilterFriendlyView, or AddWorkViewLinkedServer.

CVE-2020-27993
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.

CVE-2020-22425
Software Genérico Database
N/A
UNKNOWN
EPSS
3.4%
2020 2 PoCs

Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.

CVE-2020-10108
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

CVE-2020-0241
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151456667

CVE-2020-10548
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-24046
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin in the operating system file /etc/passwd. This file cannot be accessed though the restricted shell, but it can be modified by abusing the Backup/Import Backup functionality of the web interface. An authenticated attacker would be able to obtain the file /var/tmp/admin.passwd after executing a Backup operation. This file

CVE-2020-8215
node-canvas General
N/A
UNKNOWN
EPSS
1.9%
2020 CWE-120 1 PoC

A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.

CVE-2020-20215
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.

CVE-2020-22807
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

CVE-2020-12415
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.

CVE-2020-5540
CyberMail Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script or HTML via a specially crafted URL.

CVE-2020-23983
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.

CVE-2020-35126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.

CVE-2020-10502
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.

CVE-2020-35848
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2020 2 PoCs

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

CVE-2020-11110
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.0%
2020 1 PoC

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVE-2020-15578
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).