7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-22046
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

CVE-2020-15343
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.

CVE-2020-13877
Software Genérico Database
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.

CVE-2020-15488
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Re:Desk 2.3 allows insecure file upload.

CVE-2020-5789
Teltonika Gateway TRB245 General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

CVE-2020-10109
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2020 2 PoCs

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.

CVE-2020-9289
Fortinet FortiManager Networking
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.

CVE-2020-11553
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.

CVE-2020-8228
Nextcloud Preferred Provider Cloud
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-840 1 PoC

A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

CVE-2020-28391
SCALANCE X-200 switch family (incl. SIPLUS NET variants) General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-321 1 PoC

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (All versions < V3.2.7). Devices create a new unique key upon factory reset, except when used with C-PLUG. When used with C-PLUG the devices use the hardcoded private RSA-key shipped with the firmware-image. An attacker could leverage this situation to a man-in-the-middle situation and decrypt previously captured traffic.

CVE-2020-7605
gulp-tape General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.

CVE-2020-15568
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 2 PoCs

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

CVE-2020-23049
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-25284
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

CVE-2020-0754
Windows Windows
N/A
UNKNOWN
EPSS
13.1%
2020 2 PoCs

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.

CVE-2020-13847
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

CVE-2020-9019
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.

CVE-2020-15931
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.3%
2020 2 PoCs

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

CVE-2020-26102
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

CVE-2020-8227
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-22 2 PoCs

Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.