7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-8945
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVE-2020-13159
Software Genérico General
N/A
UNKNOWN
EPSS
17.6%
2020 1 PoC

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.

CVE-2020-13826
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.

CVE-2020-0114
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 8 PoCs

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

CVE-2020-23046
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.

CVE-2020-9036
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.2%
2020 1 PoC

Jeedom through 4.0.38 allows XSS.

CVE-2020-36222
Software Genérico Windows
N/A
UNKNOWN
EPSS
39.3%
2020 3 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service.

CVE-2020-11147
Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-21827
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379.

CVE-2020-6613
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

CVE-2020-13121
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 0 PoCs

Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

CVE-2020-10173
Software Genérico General
N/A
UNKNOWN
EPSS
56.1%
2020 1 PoC

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

CVE-2020-10223
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

CVE-2020-24709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.

CVE-2020-8221
Pulse Connect Secure General
N/A
UNKNOWN
EPSS
2.1%
2020 CWE-22 1 PoC

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

CVE-2020-27602
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

CVE-2020-15301
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.

CVE-2020-25624
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.

CVE-2020-16160
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a crash.

CVE-2020-28039
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.0%
2020 1 PoC

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.