7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-23874
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.

CVE-2020-2096
Jenkins Gitlab Hook Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2020 1 PoC

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

CVE-2020-28038
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
16.0%
2020 1 PoC

WordPress before 5.5.2 allows stored XSS via post slugs.

CVE-2020-18326
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

CVE-2020-11240
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy of the user argument in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-9273
Software Genérico General
N/A
UNKNOWN
EPSS
62.3%
2020 1 PoC

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

CVE-2020-6550
Chrome General
N/A
UNKNOWN
EPSS
17.7%
2020 1 PoC

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-28976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.2%
2020 1 PoC

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

CVE-2020-8194
Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2020 CWE-94 0 PoCs

Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

CVE-2020-35271
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.

CVE-2020-23761
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.

CVE-2020-15871
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 3 PoCs

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

CVE-2020-3833
Safari General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.

CVE-2020-22002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.

CVE-2020-35495
binutils General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-476 1 PoC

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

CVE-2020-6449
Chrome General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16288
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-15343
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

CVE-2020-20276
Software Genérico General
N/A
UNKNOWN
EPSS
4.6%
2020 1 PoC

An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.