7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-9345
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.

CVE-2020-11922
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi network the device is connected to. (Various resources such as wigle.net can be use for mapping of SSIDs to physical locations.)

CVE-2020-16219
Delta Electronics TPEditor General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-125 1 PoC

Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVE-2020-7561
Easergy T300 with firmware 2.7 and older General
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-284 1 PoC

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.

CVE-2020-13415
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.

CVE-2020-15322
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

CVE-2020-15828
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.

CVE-2020-13158
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.2%
2020 1 PoC

Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.

CVE-2020-0798
Windows Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0779, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.

CVE-2020-28871
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 5 PoCs

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVE-2020-11972
Apache Camel Web
N/A
UNKNOWN
EPSS
6.9%
2020 2 PoCs

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-15693
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.

CVE-2020-17446
Software Genérico Database
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

CVE-2020-35536
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-26110
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).

CVE-2020-15498
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. The router accepts an arbitrary server certificate for a firmware update. The culprit is the --no-check-certificate option passed to wget tool used to download firmware update files.

CVE-2020-26564
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.

CVE-2020-24794
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.

CVE-2020-36228
Software Genérico Windows
N/A
UNKNOWN
EPSS
73.5%
2020 3 PoCs

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing, resulting in denial of service.

CVE-2020-8237
json-bigint General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-400 1 PoC

Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.