7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7473
Software Genérico Networking
N/A
UNKNOWN
EPSS
67.1%
2020 1 PoC

In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version that was in use when a particular setup step was performed, NOT the product version that is in use during a current assessment of a CVE consumer's product inventory. Specifically, the vulnerability can be exploited if a storage zone was created by one of these product versions: 5.9.

CVE-2020-6615
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

CVE-2020-24038
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

CVE-2020-29604
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in MantisBT before 2.24.4. A missing access check in bug_actiongroup.php allows an attacker (with rights to create new issues) to use the COPY group action to create a clone, including all bugnotes and attachments, of any private issue (i.e., one having Private view status, or belonging to a private Project) via the bug_arr[] parameter. This provides full access to potentially confidential information.

CVE-2020-35427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-25210
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

CVE-2020-24032
Software Genérico General
N/A
UNKNOWN
EPSS
13.8%
2020 2 PoCs

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

CVE-2020-23044
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

CVE-2020-0665
Windows Windows
N/A
UNKNOWN
EPSS
7.4%
2020 1 PoC

An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

CVE-2020-23839
Software Genérico Web
N/A
UNKNOWN
EPSS
16.9%
2020 4 PoCs

A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.

CVE-2020-22024
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Buffer Overflow vulnerability in FFmpeg 4.2 at the lagfun_frame16 function in libavfilter/vf_lagfun.c, which could let a remote malicious user cause Denial of Service.

CVE-2020-10433
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-users.php by adding a question mark (?) followed by the payload.

CVE-2020-23874
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.

CVE-2020-2096
Jenkins Gitlab Hook Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2020 1 PoC

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

CVE-2020-28038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

WordPress before 5.5.2 allows stored XSS via post slugs.

CVE-2020-18326
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

CVE-2020-6550
Chrome General
N/A
UNKNOWN
EPSS
17.7%
2020 1 PoC

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-28976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.2%
2020 1 PoC

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

CVE-2020-8194
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2020 CWE-94 0 PoCs

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

CVE-2020-35271
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.