7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-11207
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655, MSM8952, MSM8956, MSM8976, MSM8976SG, MSM8996, MSM8996SG, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115,

CVE-2020-25744
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2020 3 PoCs

SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.

CVE-2020-36048
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

CVE-2020-13782
Software Genérico General
N/A
UNKNOWN
EPSS
10.1%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

CVE-2020-7646
curlrequest General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

CVE-2020-10846
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

CVE-2020-9967
tvOS General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVE-2020-35530
LibRaw General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-787 1 PoC

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

CVE-2020-13398
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.

CVE-2020-24377
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

CVE-2020-9435
Software Genérico Networking Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 4 PoCs

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.

CVE-2020-25686
dnsmasq General
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-358 1 PoC

A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to substantially reduce the number of attempts that it would have to perform to forge a reply and have it accepted by dnsmasq. This issue is mentioned in the "Birthday Attacks" section of RFC5452. If chained with CVE-2020-25684, the attack

CVE-2020-15363
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
14.2%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

CVE-2020-8004
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2020 1 PoC

STMicroelectronics STM32F1 devices have Incorrect Access Control.

CVE-2020-20746
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 1 PoC

A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.

CVE-2020-10410
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-user.php by adding a question mark (?) followed by the payload.

CVE-2020-8115
https://github.com/revive-adserver/revive-adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
50.9%
2020 CWE-79 1 PoC

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printed back without proper escaping in a JavaScript context, allowing an attacker to execute arbitrary JS

CVE-2020-25952
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2020 3 PoCs

SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-22623
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information.