7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25624
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.

CVE-2020-16160
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

GoPro gpmf-parser 1.5 has a division-by-zero vulnerability in GPMF_Decompress(). Parsing malicious input can result in a crash.

CVE-2020-28039
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.0%
2020 1 PoC

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVE-2020-15775
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.

CVE-2020-28203
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).

CVE-2020-7500
U.motion Servers and Touch Panels (affected versions listed in the security notification) Database
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-89 1 PoC

A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.

CVE-2020-12803
LibreOffice General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to m

CVE-2020-25444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.

CVE-2020-28279
flattenizer General
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-25374
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

CVE-2020-19275
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.

CVE-2020-14413
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.7%
2020 0 PoCs

NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php. This function attempts to escape the SCRIPT tag from user-controllable values, but can be easily bypassed, as demonstrated by an onerror attribute of an IMG element as a Devices-Config.php?sta= value.

CVE-2020-28092
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=

CVE-2020-21991
Software Genérico Web
N/A
UNKNOWN
EPSS
5.3%
2020 2 PoCs

AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.

CVE-2020-12672
Software Genérico General
N/A
UNKNOWN
EPSS
2.7%
2020 1 PoC

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

CVE-2020-7020
Elasticsearch Database
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-270 1 PoC

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the existence of documents the attacker should not be able to view. This could result in an attacker gaining additional insight into potentially sensitive indices.

CVE-2020-14322
Moodle General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-770 1 PoC

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVE-2020-16213
Advantech WebAccess HMI Designer General
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-787 1 PoC

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

CVE-2020-29043
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.