7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-24133
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2020 1 PoC

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

CVE-2020-8167
http://github.com/rails/rails Web
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-352 1 PoC

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

CVE-2020-10387
Software Genérico Web
N/A
UNKNOWN
EPSS
12.8%
2020 4 PoCs

Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.

CVE-2020-5502
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.

CVE-2020-6567
Chrome Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVE-2020-25950
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.

CVE-2020-6495
Chrome General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVE-2020-19625
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2020 0 PoCs

Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.

CVE-2020-11280
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-21994
Software Genérico General
N/A
UNKNOWN
EPSS
4.7%
2020 3 PoCs

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.

CVE-2020-7596
codecov npm module General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.

CVE-2020-35327
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php

CVE-2020-26050
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file. This issue is similar to CVE-2019-12572.

CVE-2020-10218
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function.

CVE-2020-10402
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-category.php by adding a question mark (?) followed by the payload.

CVE-2020-0380
Android General
N/A
UNKNOWN
EPSS
5.6%
2020 1 PoC

In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979

CVE-2020-11171
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-35226
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.

CVE-2020-10478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.

CVE-2020-27019
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.