7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-17523
Apache Shiro Web
N/A
UNKNOWN
EPSS
88.8%
2020 1 PoC

Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

CVE-2020-14066
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2020 3 PoCs

IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.

CVE-2020-29654
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

CVE-2020-11890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration.

CVE-2020-11141
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap configuration request received from peer device.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, SA415M, SA515M, SC8180X, SDX55, SM8250

CVE-2020-15719
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

CVE-2020-21602
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.

CVE-2020-10942
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.

CVE-2020-7457
FreeBSD General
N/A
UNKNOWN
EPSS
44.6%
2020 1 PoC

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

CVE-2020-36034
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVE-2020-8680
Intel(R) Graphics Drivers Advisory General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-23161
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

CVE-2020-22428
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.

CVE-2020-6843
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 3 PoCs

Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.

CVE-2020-13450
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

CVE-2020-11463
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

CVE-2020-12821
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

CVE-2020-12052
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2020-14295
Software Genérico Web Database
N/A
UNKNOWN
EPSS
81.2%
2020 5 PoCs

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

CVE-2020-18114
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.