7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12243
Software Genérico Windows
N/A
UNKNOWN
EPSS
10.8%
2020 2 PoCs

In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash).

CVE-2020-14155
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

CVE-2020-15943
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2020 3 PoCs

An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.

CVE-2020-25279
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).

CVE-2020-28133
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

CVE-2020-28243
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.

CVE-2020-16094
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.

CVE-2020-25786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

CVE-2020-19822
Software Genérico Web
N/A
UNKNOWN
EPSS
3.4%
2020 1 PoC

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.

CVE-2020-25673
Linux Kernel General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-400 1 PoC

A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.

CVE-2020-10697
Tower DevOps
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-862 1 PoC

A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce the Tower performance, for which memcached is designed. Theoretically, more sophisticated attacks can be performed by manipulating and crafting the cache, as Tower relies on memcached as a place to pull out setting values. Confidential and sensitive data stored in memcached should n

CVE-2020-14422
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.

CVE-2020-28032
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
25.8%
2020 2 PoCs

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVE-2020-6432
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-24900
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

CVE-2020-13795
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

CVE-2020-23048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

CVE-2020-8175
jpeg-js General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-400 1 PoC

Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.

CVE-2020-8437
Software Genérico General
N/A
UNKNOWN
EPSS
18.2%
2020 3 PoCs

The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.

CVE-2020-27302
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.