7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13340
GitLab DevOps Web
8.7
HIGH
EPSS
1.5%
2020 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log

CVE-2020-37214
Voyager General
8.7
HIGH
EPSS
0.5%
2020 CWE-22 1 PoC

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

CVE-2020-11066
TYPO3 CMS Web
8.7
HIGH
EPSS
0.5%
2020 CWE-915 1 PoC

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering deletion of an arbitrary directory in the file system, if it is writable for the web server. It can also trigger message submission via email using the identity of the web site (mail relay). Another insecure deserialization vulnerability is required to actually exploit mentioned aspects. This has been fixed in 9.5.17 and 10

CVE-2020-5421
Spring Framework Web
8.7
HIGH
EPSS
63.8%
2020 7 PoCs

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVE-2020-37146
Aptina AR0130 960P 1.3MP Camera General
8.7
HIGH
EPSS
0.0%
2020 CWE-306 1 PoC

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system settings.

CVE-2020-36939
Cassandra Web Web Database
8.7
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cassandra database credentials.

CVE-2020-36950
Laravel Nova DevOps Web
8.7
HIGH
EPSS
0.1%
2020 CWE-770 1 PoC

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.

CVE-2020-37113
GUnet OpenEclass Web
8.7
HIGH
EPSS
0.2%
2020 CWE-434 1 PoC

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature.

CVE-2020-15227
application Web ⚡ nuclei
8.7
HIGH
EPSS
93.8%
2020 CWE-74 4 PoCs

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

CVE-2020-37097
EW-7438RPn Mini General
8.7
HIGH
EPSS
0.1%
2020 CWE-522 1 PoC

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

CVE-2020-36946
SyncBreeze DevOps
8.7
HIGH
EPSS
0.2%
2020 CWE-770 1 PoC

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.

CVE-2020-36896
QiHang Media Web Digital Signage General
8.7
HIGH
EPSS
1.4%
2020 CWE-522 2 PoCs

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.

CVE-2020-37023
Koken CMS Web
8.7
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request through a web proxy and changing the file extension.

CVE-2020-36964
YATinyWinFTP General
8.7
HIGH
EPSS
0.1%
2020 CWE-787 1 PoC

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

CVE-2020-37034
HelloWeb General
8.7
HIGH
EPSS
0.2%
2020 CWE-22 1 PoC

HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive configuration and system files.

CVE-2020-11026
WordPress Web Windows
8.7
HIGH
EPSS
4.4%
2020 CWE-707 1 PoC

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

CVE-2020-36963
Intelbras Router RF 301K Web Networking
8.7
HIGH
EPSS
0.3%
2020 CWE-306 1 PoC

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

CVE-2020-36893
i-Media Server Digital Signage General
8.7
HIGH
EPSS
6.9%
2020 CWE-22 2 PoCs

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.

CVE-2020-36969
M/Monit Web
8.7
HIGH
EPSS
0.1%
2020 CWE-863 1 PoC

M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.

CVE-2020-36850
JSS React Sample Application General
8.7
HIGH
EPSS
0.1%
2020 CWE-200 1 PoC

An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.