7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-9287
Fortinet FortiClient EMS Networking
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

CVE-2020-7457
FreeBSD General
N/A
UNKNOWN
EPSS
44.6%
2020 1 PoC

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.

CVE-2020-36034
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVE-2020-8680
Intel(R) Graphics Drivers Advisory General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-23161
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.

CVE-2020-22428
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2020 1 PoC

SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.

CVE-2020-6843
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2020 3 PoCs

Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.

CVE-2020-13450
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

CVE-2020-11463
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

CVE-2020-12821
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

CVE-2020-12052
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2020-14295
Software Genérico Web Database
N/A
UNKNOWN
EPSS
81.2%
2020 5 PoCs

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

CVE-2020-18114
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

CVE-2020-25454
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe.

CVE-2020-6793
Thunderbird General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.

CVE-2020-13835
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).

CVE-2020-24999
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

There is an invalid memory access in the function fprintf located in Error.cc in Xpdf 4.0.2. It can be triggered by sending a crafted PDF file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVE-2020-8636
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 2 PoCs

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

CVE-2020-13093
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.