7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-35745
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

CVE-2020-16263
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

CVE-2020-28840
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).

CVE-2020-28011
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Exim 4 before 4.94.2 allows Heap-based Buffer Overflow in queue_run via two sender options: -R and -S. This may cause privilege escalation from exim to root.

CVE-2020-0569
Intel(R) PROSet/Wireless WiFi products on Windows 10 Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-0534
Intel(R) CSME General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-24876
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.

CVE-2020-20470
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.

CVE-2020-11863
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).

CVE-2020-20212
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVE-2020-9979
tvOS Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.

CVE-2020-26932
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

CVE-2020-6920
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-11723
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

CVE-2020-14416
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.

CVE-2020-26977
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

CVE-2020-0533
Intel(R) CSME General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2020-10002
watchOS Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.

CVE-2020-7663
websocket-extensions (ruby) General
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be abused by an attacker to conduct Regex Denial Of Service (ReDoS) on a single-threaded server by providing a malicious payload with the Sec-WebSocket-Extensions header.

CVE-2020-26557
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time).