7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-27368
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /icons/ directories via GET Parameter.

CVE-2020-28032
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
25.8%
2020 2 PoCs

WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

CVE-2020-6432
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-27751
ImageMagick General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-190 1 PoC

A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

CVE-2020-8175
jpeg-js General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-400 1 PoC

Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.

CVE-2020-23048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.

CVE-2020-25645
kernel General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-319 1 PoC

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.

CVE-2020-14456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.

CVE-2020-27815
Linux Kernel General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-119 2 PoCs

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2020-13394
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/SetNetControlList list parameter for a POST request, a value is directly used in a strcpy to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

CVE-2020-10793
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

CodeIgniter through 4.0.0 allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. NOTE: A contributor to the CodeIgniter framework argues that the issue should not be attributed to CodeIgniter. Furthermore, the blog post reference shows an unknown website built with the CodeIgniter framework but that CodeIgniter is not responsible for introducing this issue because the framework has never provided a login screen, nor any kind of login or user management facilities beyond a Session library. Also, another reporter indicates the issue is with a cu

CVE-2020-29656
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=General&special_cgi=get_language makes it possible to reach "unknown functionality" in a "known to be easy" manner via an unspecified "public exploit."

CVE-2020-12920
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck.

CVE-2020-9961
macOS General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

CVE-2020-7907
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

CVE-2020-26163
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.

CVE-2020-27523
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.

CVE-2020-22840
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
42.7%
2020 2 PoCs

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

CVE-2020-24385
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compat/linux/linux_emul.h is not getting initialized and returns NULL from em_find().

CVE-2020-20627
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.8%
2020 0 PoCs

The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.