7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-5408
Spring Security Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-329 3 PoCs

Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

CVE-2020-10855
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

CVE-2020-28860
Software Genérico Database
N/A
UNKNOWN
EPSS
2.4%
2020 2 PoCs

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

CVE-2020-16225
Delta Electronics TPEditor General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-123 1 PoC

Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-12783
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.2%
2020 3 PoCs

Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

CVE-2020-12625
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.

CVE-2020-5193
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.

CVE-2020-35328
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Courier Management System 1.0 - 'First Name' Stored XSS

CVE-2020-15364
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

CVE-2020-12116
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.7%
2020 1 PoC

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

CVE-2020-25015
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.

CVE-2020-29323
D-Link Router DIR-885L-MFC Networking
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

CVE-2020-27209
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.

CVE-2020-10963
Software Genérico Web
N/A
UNKNOWN
EPSS
22.4%
2020 2 PoCs

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

CVE-2020-6567
Chrome Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-7959
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.

CVE-2020-6495
Chrome General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVE-2020-15830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.

CVE-2020-24711
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

CVE-2020-11795
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.