7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-6615
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

CVE-2020-14044
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin privileges could use the plugin install feature to make the server request any URL via components/market/class.market.php. This could potentially result in remote code execution. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."

CVE-2020-24032
Software Genérico General
N/A
UNKNOWN
EPSS
13.8%
2020 2 PoCs

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

CVE-2020-35427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 2 PoCs

SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

CVE-2020-5791
Nagios XI Web
N/A
UNKNOWN
EPSS
87.8%
2020 4 PoCs

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.

CVE-2020-35437
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

CVE-2020-21605
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.

CVE-2020-6443
Chrome General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.

CVE-2020-0226
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994

CVE-2020-26141
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.

CVE-2020-10209
Software Genérico General
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

CVE-2020-8648
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

CVE-2020-15495
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVE-2020-20237
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-8134
Ghost Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-918 2 PoCs

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

CVE-2020-18660
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

CVE-2020-13249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVE-2020-0427
Android General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171

CVE-2020-22029
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.