7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-25557
Software Genérico Web
N/A
UNKNOWN
EPSS
6.3%
2020 2 PoCs

In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.

CVE-2020-16024
Chrome General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVE-2020-13650
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal component, the request is blind, but through the error message it's possible to determine whether the request targeted a open service.

CVE-2020-12134
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

CVE-2020-13245
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Certain NETGEAR devices are affected by Missing SSL Certificate Validation. This affects R7000 1.0.9.6_1.2.19 through 1.0.11.100_10.2.10, and possibly R6120, R7800, R6220, R8000, R6350, R9000, R6400, RAX120, R6400v2, RBR20, R6800, XR300, R6850, XR500, and R7000P.

CVE-2020-8189
Desktop Client Web Cloud
N/A
UNKNOWN
EPSS
0.6%
2020 CWE-79 2 PoCs

A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.

CVE-2020-0097
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 5 PoCs

In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead to local escalation of privilege with User privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-145981139

CVE-2020-0471
Android General
N/A
UNKNOWN
EPSS
2.5%
2020 1 PoC

In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-169327567.

CVE-2020-5187
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

CVE-2020-25654
pacemaker General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-284 1 PoC

An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

CVE-2020-7944
Continuous Delivery for Puppet Enterprise (CD4PE) General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.

CVE-2020-22198
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.

CVE-2020-29374
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58.

CVE-2020-13449
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

CVE-2020-10239
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

CVE-2020-6861
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A flawed protocol design in the Ledger Monero app before 1.5.1 for Ledger Nano and Ledger S devices allows a local attacker to extract the master spending key by sending crafted messages to this app selected on a PIN-entered Ledger connected to a host PC.

CVE-2020-15526
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS security checks are also ignored during monitoring of VMware machines. This would make SQL Monitor vulnerable to potential man-in-the-middle attacks when sending alert notification emails, posting to Slack or posting to webhooks. The vulnerability is fixed in version 10.1.7.

CVE-2020-25643
kernel General
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-20 2 PoCs

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-13993
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.

CVE-2020-29001
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.