7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7769
nodemailer General
8.6
HIGH
EPSS
0.5%
2020 2 PoCs

This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

CVE-2020-14611
WebCenter Portal Web Database
8.6
HIGH
EPSS
1.2%
2020 1 PoC

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data and unauthorized ability to ca

CVE-2020-37117
jizhiCMS Web
8.6
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger unauthorized file downloads.

CVE-2020-14824
Financial Services Analytical Applications Infrastructure Web Database
8.6
HIGH
EPSS
1.1%
2020 1 PoC

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. While the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in un

CVE-2020-28590
Slic3r General
8.6
HIGH
EPSS
0.3%
2020 CWE-20 2 PoCs

An out-of-bounds read vulnerability exists in the Obj File TriangleMesh::TriangleMesh() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted obj file could lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-1745
undertow General
8.6
HIGH
EPSS
0.6%
2020 CWE-285 2 PoCs

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution.

CVE-2020-36880
DiskBoss General
8.6
HIGH
EPSS
0.0%
2020 CWE-119 1 PoC

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system.

CVE-2020-3566
🔥 KEV Cisco IOS XR Software Networking
8.6
HIGH
EPSS
2.1%
2020 CWE-400 1 PoC

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior an

CVE-2020-37137
PHP Fusion Web
8.6
HIGH
EPSS
0.0%
2020 CWE-95 1 PoC

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.

CVE-2020-17354
Software Genérico General
8.6
HIGH
EPSS
0.0%
2020 1 PoC

LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary code execution during conversion to a different file format. NOTE: in 2.24 and later versions, safe mode is removed, and the product no longer tries to block code execution when external files are used.

CVE-2020-28449
decal General
8.6
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package decal. The vulnerability is in the set function.

CVE-2020-28591
Slic3r General
8.6
HIGH
EPSS
0.3%
2020 CWE-20 2 PoCs

An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-36914
QiHang Media Web (QH.aspx) Digital Signage General
8.6
HIGH
EPSS
0.1%
2020 CWE-319 1 PoC

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

CVE-2020-37167
ClamBC General
8.6
HIGH
EPSS
0.0%
2020 1 PoC

ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the ClamAV engine.

CVE-2020-37073
CMSsite Web
8.6
HIGH
EPSS
0.1%
2020 CWE-434 1 PoC

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.

CVE-2020-7284
Network Security Management (NSM) General
8.6
HIGH
EPSS
0.0%
2020 CWE-200 1 PoC

Exposure of Sensitive Information in McAfee Network Security Management (NSM) prior to 10.1.7.7 allows local users to gain unauthorised access to the root account via execution of carefully crafted commands from the restricted command line interface (CLI).

CVE-2020-28450
decal General
8.6
HIGH
EPSS
0.4%
2020 1 PoC

This affects all versions of package decal. The vulnerability is in the extend function.

CVE-2020-37084
School ERP Pro Web
8.6
HIGH
EPSS
0.5%
2020 CWE-434 1 PoC

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

CVE-2020-36890
Xperience General
8.6
HIGH
EPSS
0.1%
2020 CWE-862 1 PoC

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

CVE-2020-2863
Advanced Outbound Telephony Web Database
8.5
HIGH
EPSS
0.5%
2020 1 PoC

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. While the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessib