7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-21990
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2020 2 PoCs

Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specially crafted request to gain access to sensitive information.

CVE-2020-0226
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994

CVE-2020-26141
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.

CVE-2020-10209
Software Genérico General
N/A
UNKNOWN
EPSS
3.1%
2020 1 PoC

Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

CVE-2020-8648
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

CVE-2020-29474
Software Genérico Database
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.

CVE-2020-28976
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.2%
2020 1 PoC

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

CVE-2020-6550
Chrome General
N/A
UNKNOWN
EPSS
17.7%
2020 1 PoC

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15495
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVE-2020-20237
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.

CVE-2020-8134
Ghost Web
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-918 2 PoCs

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

CVE-2020-18660
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

CVE-2020-13249
Software Genérico Database
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

libmariadb/mariadb_lib.c in MariaDB Connector/C before 3.1.8 does not properly validate the content of an OK packet received from a server. NOTE: although mariadb_lib.c was originally based on code shipped for MySQL, this issue does not affect any MySQL components supported by Oracle.

CVE-2020-0427
Android General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171

CVE-2020-22029
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 at libavfilter/vf_colorconstancy.c: in slice_get_derivative, which crossfade_samples_fltp, which might lead to memory corruption and other potential consequences.

CVE-2020-22046
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

CVE-2020-13877
Software Genérico Database
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.

CVE-2020-15488
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Re:Desk 2.3 allows insecure file upload.

CVE-2020-5789
Teltonika Gateway TRB245 General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

CVE-2020-10109
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 2 PoCs

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.