7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7136
Smart Update Manager (SUM) Web ⚡ nuclei
N/A
UNKNOWN
EPSS
63.3%
2020 1 PoC

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

CVE-2020-7604
pulverizr General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.

CVE-2020-27844
openjpeg General
N/A
UNKNOWN
EPSS
2.0%
2020 CWE-20 3 PoCs

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0. This flaw allows an attacker to provide crafted input to openjpeg during conversion and encoding, causing an out-of-bounds write. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-11124
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'Possible use-after-free while accessing diag client map table since list can be reallocated due to exceeding max client limit.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCS404, QCS405, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC8180X, SDM660, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

CVE-2020-5748
TCExam Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-15337
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.

CVE-2020-9442
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.

CVE-2020-11490
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.

CVE-2020-8184
https://github.com/rack/rack Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-784 3 PoCs

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

CVE-2020-13625
Software Genérico Web
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.

CVE-2020-25659
python-cryptography Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-385 2 PoCs

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

CVE-2020-21884
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.

CVE-2020-35556
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

CVE-2020-24490
BlueZ Advisory General
N/A
UNKNOWN
EPSS
4.5%
2020 2 PoCs

Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.

CVE-2020-6484
Chrome General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.

CVE-2020-15849
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the applicati

CVE-2020-18898
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

CVE-2020-23148
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.

CVE-2020-12841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php