7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7613
clamscan General
N/A
UNKNOWN
EPSS
1.8%
2020 1 PoC

clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.

CVE-2020-13852
Software Genérico General
N/A
UNKNOWN
EPSS
31.1%
2020 2 PoCs

Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.

CVE-2020-13380
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

openSIS before 7.4 allows SQL Injection.

CVE-2020-8000
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

CVE-2020-24550
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2020 1 PoC

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

CVE-2020-7235
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).

CVE-2020-35752
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 3 PoCs

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVE-2020-7995
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

CVE-2020-13465
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.

CVE-2020-12891
Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVE-2020-29053
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.

CVE-2020-10499
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

CVE-2020-11138
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-2230
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVE-2020-23040
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands.

CVE-2020-35717
Software Genérico Web
N/A
UNKNOWN
EPSS
6.1%
2020 4 PoCs

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

CVE-2020-5809
Umbraco CMS Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.

CVE-2020-15333
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.

CVE-2020-11415
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

CVE-2020-27821
QEMU Web
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.