7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-8799
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.

CVE-2020-6954
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_folder.cgi?apply_mode=ping_server URI.

CVE-2020-3680
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A race condition can occur when using the fastrpc memory mapping API. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MSM8909W, MSM8917, MSM8953, QCS605, QM215, SA415M, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SXR1130

CVE-2020-25708
libvncserver General
N/A
UNKNOWN
EPSS
0.7%
2020 CWE-369 1 PoC

A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.

CVE-2020-6612
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

CVE-2020-12897
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

CVE-2020-13414
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

CVE-2020-24963
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.

CVE-2020-3658
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Possible null-pointer dereference can occur while parsing mp4 clip with corrupted sample table atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM7

CVE-2020-12848
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 3 PoCs

In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backend with a random username. An anonymous user that obtains a valid public link can get the associated hidden account username and password and proceed to login to the web application. Once logged into the web application with the hidden user account, some actions that were not available with the public share link can now be performed.

CVE-2020-13380
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

openSIS before 7.4 allows SQL Injection.

CVE-2020-8000
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

CVE-2020-24550
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2020 1 PoC

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

CVE-2020-7235
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).

CVE-2020-35752
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVE-2020-7995
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

CVE-2020-13465
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.

CVE-2020-12891
Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVE-2020-29053
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.