7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25659
python-cryptography Web
N/A
UNKNOWN
EPSS
0.8%
2020 CWE-385 2 PoCs

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

CVE-2020-21884
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.

CVE-2020-35556
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

CVE-2020-24490
BlueZ Advisory General
N/A
UNKNOWN
EPSS
4.5%
2020 2 PoCs

Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.

CVE-2020-23038
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables.

CVE-2020-6484
Chrome General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.

CVE-2020-15849
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the applicati

CVE-2020-18898
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.

CVE-2020-23148
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.

CVE-2020-12841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php

CVE-2020-10393
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-field.php by adding a question mark (?) followed by the payload.

CVE-2020-15389
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 3 PoCs

jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be possible. This is related to calling opj_image_destroy twice.

CVE-2020-12832
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2020 0 PoCs

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVE-2020-12960
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).

CVE-2020-7499
U.motion Servers and Touch Panels (affected versions listed in the security notification) General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-863 1 PoC

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause unauthorized access when a low privileged user makes unauthorized changes.

CVE-2020-22841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

CVE-2020-28904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

CVE-2020-35548
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).

CVE-2020-11971
Apache Camel Web
N/A
UNKNOWN
EPSS
9.7%
2020 3 PoCs

Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.