7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7650
snyk-broker General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.

CVE-2020-28268
controlled-merge General
N/A
UNKNOWN
EPSS
2.3%
2020 2 PoCs

Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-12757
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.

CVE-2020-23762
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.

CVE-2020-10403
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-comment.php by adding a question mark (?) followed by the payload.

CVE-2020-24576
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

CVE-2020-10435
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/my-languages.php by adding a question mark (?) followed by the payload.

CVE-2020-6807
Thunderbird General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-15053
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
11.8%
2020 1 PoC

An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects.

CVE-2020-28010
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Exim 4 before 4.94.2 allows Out-of-bounds Write because the main function, while setuid root, copies the current working directory pathname into a buffer that is too small (on some common platforms).

CVE-2020-12926
AMD's fTPM implementation General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-367 1 PoC

The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power must be repeatedly turned on and off. This potential attack may be used to change confidential information, alter executables signed by key material in the TPM, or create a denial of service of the device.

CVE-2020-27845
openjpeg General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-125 3 PoCs

There's a flaw in src/lib/openjp2/pi.c of openjpeg in versions prior to 2.4.0. If an attacker is able to provide untrusted input to openjpeg's conversion/encoding functionality, they could cause an out-of-bounds read. The highest impact of this flaw is to application availability.

CVE-2020-2094
Jenkins Health Advisor by CloudBees Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

CVE-2020-3653
Snapdragon Compute, Snapdragon Connectivity Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850

CVE-2020-14179
Jira Server General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2020 4 PoCs

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVE-2020-14962
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple XSS vulnerabilities in the Final Tiles Gallery plugin before 3.4.19 for WordPress allow remote attackers to inject arbitrary web script or HTML via the Title (aka imageTitle) or Caption (aka description) field of an image to wp-admin/admin-ajax.php.

CVE-2020-10549
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2020 0 PoCs

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CVE-2020-35575
Software Genérico General
N/A
UNKNOWN
EPSS
18.8%
2020 4 PoCs

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

CVE-2020-13151
Software Genérico General
N/A
UNKNOWN
EPSS
90.0%
2020 5 PoCs

Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.

CVE-2020-12720
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.