7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36491
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-6432
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-24900
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

CVE-2020-13795
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.

CVE-2020-23048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

CVE-2020-8175
jpeg-js General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-400 1 PoC

Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.

CVE-2020-8437
Software Genérico General
N/A
UNKNOWN
EPSS
18.2%
2020 3 PoCs

The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.

CVE-2020-27302
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

CVE-2020-27422
Software Genérico General
N/A
UNKNOWN
EPSS
10.7%
2020 1 PoC

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

CVE-2020-15582
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth Low Energy (BLE) component has a buffer overflow with a resultant deadlock or crash. The Samsung ID is SVE-2020-16870 (July 2020).

CVE-2020-35525
sqlite Database
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-476 1 PoC

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

CVE-2020-27622
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.

CVE-2020-23560
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.

CVE-2020-11507
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.

CVE-2020-11825
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

CVE-2020-5787
Teltonika Gateway TRB245 General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.

CVE-2020-28019
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2020 1 PoC

Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.

CVE-2020-35774
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.9%
2020 0 PoCs

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

CVE-2020-35337
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.

CVE-2020-26602
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (October 2020).