7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-27744
Software Genérico Cloud
N/A
UNKNOWN
EPSS
10.4%
2020 1 PoC

An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.

CVE-2020-6440
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.

CVE-2020-3668
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130

CVE-2020-9374
Software Genérico General
N/A
UNKNOWN
EPSS
87.3%
2020 2 PoCs

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

CVE-2020-7108
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.3%
2020 3 PoCs

The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.

CVE-2020-12988
1st/2nd/3rd Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.

CVE-2020-35448
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.

CVE-2020-8136
fastify-multipart General
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-400 1 PoC

Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request.

CVE-2020-8121
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-284 1 PoC

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

CVE-2020-5395
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

CVE-2020-14355
spice Cloud
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-120 2 PoCs

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

CVE-2020-0453
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-8.0 Android-8.1Android ID: A-159060474

CVE-2020-15598
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2020 3 PoCs

Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition. The vendor does not consider this as a security issue because1) there is no default configuration issue here. An attacker would need to know that a rule using a potentially problematic regular expression was in place, 2) the attacker would need to know the basic nature of the reg

CVE-2020-23864
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the WindowsApps folder.

CVE-2020-23814
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.7%
2020 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.

CVE-2020-26165
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.

CVE-2020-5765
Tenable Nessus Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.

CVE-2020-29071
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information about encrypted e-mails, depending on the permissions of the target user.

CVE-2020-7660
serialize-javascript Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".