7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-24366
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

CVE-2020-35531
LibRaw General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-125 1 PoC

In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

CVE-2020-26098
Software Genérico General
N/A
UNKNOWN
EPSS
9.8%
2020 1 PoC

cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

CVE-2020-10441
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-article-monthly.php by adding a question mark (?) followed by the payload.

CVE-2020-7609
node-rules General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.

CVE-2020-25905
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.

CVE-2020-16251
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.

CVE-2020-6162
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.

CVE-2020-29372
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.

CVE-2020-12647
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Unisys ALGOL Compiler 58.1 before 58.1a.15, 59.1 before 59.1a.9, and 60.0 before 60.0a.5 can emit invalid code sequences under rare circumstances related to syntax. The resulting code could, for example, trigger a system fault or adversely affect confidentiality, integrity, and availability.

CVE-2020-8635
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2020 1 PoC

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.

CVE-2020-7243
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2020 1 PoC

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

CVE-2020-16205
G-Cam and G-Code General
N/A
UNKNOWN
EPSS
55.2%
2020 CWE-78 1 PoC

Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).

CVE-2020-12743
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a hidden_req POST parameter.

CVE-2020-10764
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-13884
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-17453
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.7%
2020 3 PoCs

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

CVE-2020-28187
Software Genérico Web
N/A
UNKNOWN
EPSS
64.2%
2020 2 PoCs

Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.

CVE-2020-28074
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

CVE-2020-21676
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.