7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-21601
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.

CVE-2020-13802
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2020 2 PoCs

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

CVE-2020-25604
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue is a hang or crash of the hypervisor, i.e., a Denial of Service (DoS). All versions of Xen are affected. Only x86 systems are vulnerable. Arm systems are not vulnerable. Only x86 HVM guests can leverage the vulnerability. x86 PV and PVH cannot leve

CVE-2020-12964
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information.

CVE-2020-25834
ArcSight Logger Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

CVE-2020-13804
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin.

CVE-2020-25495
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.

CVE-2020-13934
Apache Tomcat Web
N/A
UNKNOWN
EPSS
23.4%
2020 6 PoCs

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

CVE-2020-1967
OpenSSL General
N/A
UNKNOWN
EPSS
60.8%
2020 12 PoCs

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).

CVE-2020-10983
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.

CVE-2020-6016
Game Networking Sockets General
N/A
UNKNOWN
EPSS
6.6%
2020 CWE-590 2 PoCs

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underflow and a free() of memory not from the heap, resulting in a memory corruption and probably even a remote code execution.

CVE-2020-29288
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.

CVE-2020-24654
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.

CVE-2020-35231
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was affected by an authentication issue that allows an attacker to bypass access controls and obtain full control of the device.

CVE-2020-35852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.

CVE-2020-12860
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.

CVE-2020-27151
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.

CVE-2020-11883
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2020 1 PoC

In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.

CVE-2020-7653
snyk-broker General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network by creating symlinks to match whitelisted paths.

CVE-2020-36503
Connections Business Directory Web Windows
N/A
UNKNOWN
EPSS
1.3%
2020 CWE-1236 1 PoC

The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue