7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-26574
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2020 2 PoCs

Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the admin to upload a malicious Perl script that will be executed as root via libMisc::browser_client. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2020-9277
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.

CVE-2020-13890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.

CVE-2020-28884
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2020 3 PoCs

Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw.

CVE-2020-3676
Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE-2020-12929
AMD Radeon Software General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution .

CVE-2020-8153
Nextcloud Groupfolders Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-284 1 PoC

Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.

CVE-2020-13451
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.

CVE-2020-15677
Firefox General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.

CVE-2020-10568
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

CVE-2020-28001
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2020 2 PoCs

SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.

CVE-2020-28133
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

CVE-2020-28243
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

CVE-2020-16094
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

CVE-2020-25786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

CVE-2020-19822
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

CVE-2020-25673
Linux Kernel General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-400 1 PoC

A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.

CVE-2020-10697
Tower DevOps
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-862 1 PoC

A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce the Tower performance, for which memcached is designed. Theoretically, more sophisticated attacks can be performed by manipulating and crafting the cache, as Tower relies on memcached as a place to pull out setting values. Confidential and sensitive data stored in memcached should n

CVE-2020-14422
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.

CVE-2020-28032
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
25.8%
2020 2 PoCs

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.