7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13151
Software Genérico General
N/A
UNKNOWN
EPSS
90.0%
2020 5 PoCs

Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with network access can use a crafted UDF to execute arbitrary OS commands on all nodes of the cluster at the permission level of the user running the Aerospike service.

CVE-2020-12720
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2020 3 PoCs

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

CVE-2020-28146
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.

CVE-2020-14199
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

BIP-143 in the Bitcoin protocol specification mishandles the signing of a Segwit transaction, which allows attackers to trick a user into making two signatures in certain cases, potentially leading to a huge transaction fee. NOTE: this affects all hardware wallets. It was fixed in 1.9.1 for the Trezor One and 2.3.1 for the Trezor Model T.

CVE-2020-14073
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.

CVE-2020-19907
Software Genérico General
N/A
UNKNOWN
EPSS
10.9%
2020 1 PoC

A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.

CVE-2020-13248
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.

CVE-2020-12835
Software Genérico Web
N/A
UNKNOWN
EPSS
5.0%
2020 4 PoCs

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.

CVE-2020-9467
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

CVE-2020-27974
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.

CVE-2020-28015
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters. Local users can alter the behavior of root processes because a recipient address can have a newline character.

CVE-2020-11698
Software Genérico Web
N/A
UNKNOWN
EPSS
84.2%
2020 3 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

CVE-2020-5762
Grandstream HT800 Series Web
N/A
UNKNOWN
EPSS
4.6%
2020 CWE-476 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

CVE-2020-7220
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.

CVE-2020-11690
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.

CVE-2020-0543
Intel(R) Processors General
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-28367
cmd/go General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVE-2020-14032
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.

CVE-2020-15003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).

CVE-2020-25744
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.