7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15492
Software Genérico General
N/A
UNKNOWN
EPSS
37.7%
2020 4 PoCs

An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.

CVE-2020-35576
Software Genérico General
N/A
UNKNOWN
EPSS
71.2%
2020 1 PoC

A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.

CVE-2020-7623
jscover General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

CVE-2020-23977
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.

CVE-2020-15367
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2020 1 PoC

Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

CVE-2020-20977
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.

CVE-2020-13422
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.

CVE-2020-18730
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).

CVE-2020-1934
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
27.2%
2020 1 PoC

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

CVE-2020-24701
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.9%
2020 3 PoCs

OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).

CVE-2020-15972
Chrome General
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-11117
Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980

CVE-2020-6586
Software Genérico Web
N/A
UNKNOWN
EPSS
7.3%
2020 1 PoC

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.

CVE-2020-15579
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via the KNOX API. The Samsung ID is SVE-2020-17318 (July 2020).

CVE-2020-8116
dot-prop Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-471 2 PoCs

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

CVE-2020-27403
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows an attacker on the adjacent network to arbitrarily browse and download sensitive files over an insecure web server running on port 7989 that lists all files & directories. An unprivileged remote attacker on the adjacent network, can download most system files, leading to serious critical information disclosure. Also, some TV models and/or FW versions may expose the webserver with the entire filesystem accessible on another port. For examp

CVE-2020-11491
Software Genérico General
N/A
UNKNOWN
EPSS
65.5%
2020 1 PoC

Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.

CVE-2020-11452
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper.

CVE-2020-35745
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVE-2020-16263
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.