7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-11605
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).

CVE-2020-8442
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.

CVE-2020-6435
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

CVE-2020-35716
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to cause a persistent denial of service (segmentation fault) via a long /goform/langSwitch langSelectionOnly parameter.

CVE-2020-8608
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.

CVE-2020-8231
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-416 2 PoCs

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data.

CVE-2020-23522
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

CVE-2020-11199
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-14372
grub2 General
N/A
UNKNOWN
EPSS
1.9%
2020 CWE-184 2 PoCs

A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.

CVE-2020-20949
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-21997
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 3 PoCs

Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information resulting in authentication bypass, session hijacking and full system control.

CVE-2020-9456
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.

CVE-2020-8990
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.

CVE-2020-7465
MPD: FreeBSD PPP daemon General
N/A
UNKNOWN
EPSS
3.0%
2020 CWE-787 1 PoC

The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).

CVE-2020-11973
Apache Camel Web
N/A
UNKNOWN
EPSS
14.1%
2020 5 PoCs

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-8154
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
1.0%
2020 CWE-639 1 PoC

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

CVE-2020-13444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

CVE-2020-15352
Software Genérico General
N/A
UNKNOWN
EPSS
6.6%
2020 1 PoC

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVE-2020-9758
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from unauthenticated to user-level access, leading to full account takeover. The attack fetches multiple credentials because they are stored in the database (stored XSS). This affects the mobile/chat URI via the lgn and psswrd parameters.