7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13884
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.

CVE-2020-17453
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.7%
2020 3 PoCs

WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.

CVE-2020-28187
Software Genérico Web
N/A
UNKNOWN
EPSS
64.2%
2020 2 PoCs

Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.

CVE-2020-28074
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

CVE-2020-21676
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

CVE-2020-1950
Apache Tika Web
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

CVE-2020-35328
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Courier Management System 1.0 - 'First Name' Stored XSS

CVE-2020-6170
Software Genérico General
N/A
UNKNOWN
EPSS
9.8%
2020 2 PoCs

An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

CVE-2020-11202
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Buffer overflow/underflow occurs when typecasting the buffer passed by CPU internally in the library which is not aligned with the actual size of the structure' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA670, SDA845, SDM640, SDM670, SDM710, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P

CVE-2020-24609
Software Genérico Web
N/A
UNKNOWN
EPSS
18.2%
2020 3 PoCs

TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via crafted payload.

CVE-2020-8772
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2020 1 PoC

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVE-2020-10809
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in HDF5 through 1.12.0. A heap-based buffer overflow exists in the function Decompress() located in decompress.c. It can be triggered by sending a crafted file to the gif2h5 binary. It allows an attacker to cause Denial of Service.

CVE-2020-24133
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVE-2020-8167
http://github.com/rails/rails Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-352 1 PoC

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

CVE-2020-10387
Software Genérico Web
N/A
UNKNOWN
EPSS
12.8%
2020 4 PoCs

Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

CVE-2020-5502
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

CVE-2020-19625
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2020 0 PoCs

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

CVE-2020-11280
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-21994
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 3 PoCs

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

CVE-2020-7596
codecov npm module General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.