7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-11698
Software Genérico Web
N/A
UNKNOWN
EPSS
84.2%
2020 3 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

CVE-2020-5762
Grandstream HT800 Series Web
N/A
UNKNOWN
EPSS
4.6%
2020 CWE-476 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

CVE-2020-7220
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.

CVE-2020-9423
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for multiple tasks, such as version control, shared among users, applying tags, etc. This functionality could be abused by an unauthenticated attacker to upload an arbitrary file in a restricted folder. This would lead to the executions of malicious commands with root privileges.

CVE-2020-35272
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.

CVE-2020-11690
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.

CVE-2020-0543
Intel(R) Processors General
N/A
UNKNOWN
EPSS
0.5%
2020 4 PoCs

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-28367
cmd/go General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

CVE-2020-14032
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2020 1 PoC

ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.

CVE-2020-15003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).

CVE-2020-25744
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.

CVE-2020-36048
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

CVE-2020-13782
Software Genérico General
N/A
UNKNOWN
EPSS
10.1%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

CVE-2020-7646
curlrequest General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

CVE-2020-10846
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

CVE-2020-35530
LibRaw General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVE-2020-13398
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVE-2020-24377
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

CVE-2020-9435
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 4 PoCs

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.