7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-15871
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 3 PoCs

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

CVE-2020-16307
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2020 1 PoC

A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

CVE-2020-9456
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.

CVE-2020-3833
Safari General
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.5. Visiting a malicious website may lead to address bar spoofing.

CVE-2020-22002
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service through onvif.cgi. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP request to an arbitrary destination host.

CVE-2020-35495
binutils General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-476 1 PoC

There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

CVE-2020-6449
Chrome General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16288
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-11973
Apache Camel Web
N/A
UNKNOWN
EPSS
14.1%
2020 5 PoCs

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-15343
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

CVE-2020-20276
Software Genérico General
N/A
UNKNOWN
EPSS
4.6%
2020 1 PoC

An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.

CVE-2020-11457
Software Genérico Web
N/A
UNKNOWN
EPSS
5.9%
2020 2 PoCs

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

CVE-2020-9463
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2020 1 PoC

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

CVE-2020-28858
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

CVE-2020-13805
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.

CVE-2020-15586
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.

CVE-2020-10230
Software Genérico Web Database
N/A
UNKNOWN
EPSS
28.9%
2020 1 PoC

CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

CVE-2020-8225
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-312 2 PoCs

A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

CVE-2020-10448
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php by adding a question mark (?) followed by the payload.

CVE-2020-0542
Intel(R) CSME General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.