7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-12124
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.3%
2020 2 PoCs

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

CVE-2020-9389
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.

CVE-2020-15568
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.3%
2020 2 PoCs

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

CVE-2020-23049
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-6918
HP Support Assistant General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

CVE-2020-25284
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.

CVE-2020-0754
Windows Windows
N/A
UNKNOWN
EPSS
13.1%
2020 2 PoCs

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753.

CVE-2020-13847
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

CVE-2020-9019
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.

CVE-2020-15931
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.3%
2020 2 PoCs

Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator (that is configured within the product in its installation state) by generating a single Kerberos Pre-Authentication Failed (ID 4771) event on a Domain Controller.

CVE-2020-26102
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

CVE-2020-8227
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-22 2 PoCs

Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.

CVE-2020-26061
Software Genérico Web
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.

CVE-2020-12840
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

CVE-2020-10456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/trash-box.php by adding a question mark (?) followed by the payload.

CVE-2020-14039
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVE-2020-6437
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.

CVE-2020-25754
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. Attempts to change the user password via passwd or other tools have no effect.

CVE-2020-36224
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.5%
2020 4 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVE-2020-12863
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.