7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-8227
Desktop Client Cloud
N/A
UNKNOWN
EPSS
0.9%
2020 CWE-22 2 PoCs

Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.

CVE-2020-26061
Software Genérico Web
N/A
UNKNOWN
EPSS
6.8%
2020 1 PoC

ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.

CVE-2020-12840
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php

CVE-2020-10456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/trash-box.php by adding a question mark (?) followed by the payload.

CVE-2020-14039
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate verification is incomplete.

CVE-2020-6437
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.

CVE-2020-25754
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password derived from the MD5 hash of the username and serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. Attempts to change the user password via passwd or other tools have no effect.

CVE-2020-36224
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.5%
2020 4 PoCs

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVE-2020-12863
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

CVE-2020-11503
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

CVE-2020-24642
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-12352
BlueZ General
N/A
UNKNOWN
EPSS
2.4%
2020 2 PoCs

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

CVE-2020-29304
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2020 2 PoCs

A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

CVE-2020-15928
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters to test-browser/index.cfm allow directory traversal.

CVE-2020-15855
bodhi Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-79 1 PoC

Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

CVE-2020-9021
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.

CVE-2020-8290
Backblaze Windows
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-269 3 PoCs

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

CVE-2020-10487
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.

CVE-2020-26108
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

CVE-2020-27617
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.