7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10983
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.

CVE-2020-29288
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 2 PoCs

An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.

CVE-2020-35674
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted payload that can result in sensitive information being extracted from the database, eventually leading into an application takeover. This vulnerability was introduced as a result of the developer trying to roll their own sanitization implementation in order to allow the application to be used in legacy environments.

CVE-2020-15348
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.

CVE-2020-35852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS.

CVE-2020-12860
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.

CVE-2020-3965
VMware ESXi General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the XHCI USB controller. A malicious actor with local access to a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CVE-2020-10580
Software Genérico Web
N/A
UNKNOWN
EPSS
11.0%
2020 2 PoCs

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

CVE-2020-0413
Android General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-158778659

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2020-19131
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

CVE-2020-22015
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

CVE-2020-19907
Software Genérico General
N/A
UNKNOWN
EPSS
10.9%
2020 1 PoC

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

CVE-2020-13248
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.

CVE-2020-27637
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

CVE-2020-9029
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

CVE-2020-12835
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2020 4 PoCs

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

CVE-2020-29660
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

CVE-2020-26524
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.