7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-24622
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

CVE-2020-15308
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.

CVE-2020-12424
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.

CVE-2020-15718
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.9%
2020 2 PoCs

RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL.

CVE-2020-8438
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

CVE-2020-24618
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

CVE-2020-35233
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device reboots by sending concurrent connections, aka a denial of service attack.

CVE-2020-36012
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

CVE-2020-7039
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

CVE-2020-10208
Software Genérico General
N/A
UNKNOWN
EPSS
8.3%
2020 1 PoC

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.

CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVE-2020-5748
TCExam Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-15337
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

CVE-2020-9442
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.

CVE-2020-11490
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.

CVE-2020-8184
https://github.com/rack/rack Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-784 3 PoCs

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

CVE-2020-13625
Software Genérico Web
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

CVE-2020-25659
python-cryptography Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-385 2 PoCs

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.