7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-5761
Grandstream HT800 Series General
N/A
UNKNOWN
EPSS
3.9%
2020 CWE-835 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.

CVE-2020-27556
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.

CVE-2020-24908
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Checkmk before 1.6.0p17 allows local users to obtain SYSTEM privileges via a Trojan horse shell script in the %PROGRAMDATA%\checkmk\agent\local directory.

CVE-2020-27020
Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

CVE-2020-0976
Microsoft SharePoint Enterprise Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.

CVE-2020-12137
Software Genérico Web
N/A
UNKNOWN
EPSS
5.2%
2020 1 PoC

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

CVE-2020-9476
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.

CVE-2020-35430
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.

CVE-2020-13852
Software Genérico General
N/A
UNKNOWN
EPSS
31.1%
2020 2 PoCs

Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.

CVE-2020-35685
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attacker may be able to determine the ISN of current and future TCP connections and either hijack existing ones or spoof future ones. (Proper ISN generation should aim to follow at least the specifications outlined in RFC 6528.)

CVE-2020-15308
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

CVE-2020-12424
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.

CVE-2020-8438
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

CVE-2020-24618
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

CVE-2020-35233
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

CVE-2020-36012
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

CVE-2020-7039
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVE-2020-10208
Software Genérico General
N/A
UNKNOWN
EPSS
8.3%
2020 1 PoC

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.

CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).