7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13465
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.

CVE-2020-10208
Software Genérico General
N/A
UNKNOWN
EPSS
8.3%
2020 1 PoC

Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute arbitrary commands with root user privileges.

CVE-2020-12891
Radeon Software General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.

CVE-2020-29053
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.

CVE-2020-35605
Software Genérico General
N/A
UNKNOWN
EPSS
5.5%
2020 1 PoC

The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.

CVE-2020-5748
TCExam Web
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-10499
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

CVE-2020-11138
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Uninitialized pointers accessed during music play back with incorrect bit stream due to an uninitialized heap memory result in instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2020-2230
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVE-2020-23040
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands.

CVE-2020-35717
Software Genérico Web
N/A
UNKNOWN
EPSS
6.1%
2020 4 PoCs

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

CVE-2020-5809
Umbraco CMS Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.

CVE-2020-15333
Software Genérico Database Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.

CVE-2020-11415
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

CVE-2020-27821
QEMU Web
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.

CVE-2020-29599
Software Genérico General
N/A
UNKNOWN
EPSS
68.8%
2020 3 PoCs

ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which allows setting a password for password-protected PDF files. The user-controlled password was not properly escaped/sanitized and it was therefore possible to inject additional shell commands via coders/pdf.c.

CVE-2020-11694
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.

CVE-2020-24716
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.

CVE-2020-9425
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
49.4%
2020 0 PoCs

An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

CVE-2020-36314
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.