7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7107
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.2%
2020 1 PoC

The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php.

CVE-2020-7993
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

CVE-2020-26879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.9%
2020 4 PoCs

Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the service API by using a backdoor value as the Authorization header.

CVE-2020-24373
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.

CVE-2020-22022
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.

CVE-2020-10203
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Sonatype Nexus Repository before 3.21.2 allows XSS.

CVE-2020-7621
strong-nginx-controller Web
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.

CVE-2020-26773
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.

CVE-2020-13992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a crafted ticket.

CVE-2020-8995
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.

CVE-2020-24387
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a denial of service attack.

CVE-2020-11178
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-5793
Tenable Nessus for Windows and Tenable Nessus Agent for Windows Windows
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2020-7639
@eivifj/dot General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

CVE-2020-10447
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-failed-login.php by adding a question mark (?) followed by the payload.

CVE-2020-18048
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2020 2 PoCs

An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.

CVE-2020-27488
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur.

CVE-2020-16259
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.

CVE-2020-13829
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).