7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-0413
Android General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-158778659

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2020-19131
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

CVE-2020-22015
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

CVE-2020-19907
Software Genérico General
N/A
UNKNOWN
EPSS
10.9%
2020 1 PoC

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

CVE-2020-13248
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.

CVE-2020-27637
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

CVE-2020-9029
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

CVE-2020-12835
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2020 4 PoCs

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

CVE-2020-29660
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

CVE-2020-26524
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.

CVE-2020-23551
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30.

CVE-2020-11170
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-9423
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for multiple tasks, such as version control, shared among users, applying tags, etc. This functionality could be abused by an unauthenticated attacker to upload an arbitrary file in a restricted folder. This would lead to the executions of malicious commands with root privileges.

CVE-2020-10406
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-group.php by adding a question mark (?) followed by the payload.

CVE-2020-23697
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2020 0 PoCs

Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.

CVE-2020-36311
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184.

CVE-2020-35535
LibRaw General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-125 1 PoC

In LibRaw, there is an out-of-bounds read vulnerability within the "LibRaw::parseSonySRF()" function (libraw\src\metadata\sony.cpp) when processing srf files.

CVE-2020-10770
keycloak General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 CWE-918 3 PoCs

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

CVE-2020-35249
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.