7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-13992
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a crafted ticket.

CVE-2020-8995
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2020 2 PoCs

Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.

CVE-2020-35396
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.

CVE-2020-13380
Software Genérico Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

openSIS before 7.4 allows SQL Injection.

CVE-2020-24387
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a denial of service attack.

CVE-2020-11178
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-5793
Tenable Nessus for Windows and Tenable Nessus Agent for Windows Windows
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. The attacker needs valid credentials on the Windows system to exploit this vulnerability.

CVE-2020-5405
Spring Cloud Config Web Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
88.0%
2020 CWE-23 1 PoC

Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

CVE-2020-7639
@eivifj/dot General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

CVE-2020-10447
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-failed-login.php by adding a question mark (?) followed by the payload.

CVE-2020-18048
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2020 2 PoCs

An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.

CVE-2020-27488
Software Genérico Cloud
N/A
UNKNOWN
EPSS
1.0%
2020 2 PoCs

Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofing these devices) can continue to use an unauthenticated cloud service for an indeterminate time period (possibly forever). Once an individual device's firmware is updated, and authentication occurs once, the cloud service recategorizes the device so that authentication is subsequently always required, and spoofing cannot occur.

CVE-2020-16259
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.

CVE-2020-13829
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).

CVE-2020-10851
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).

CVE-2020-14387
rsync General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-297 1 PoC

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.

CVE-2020-0537
Intel(R) AMT General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

CVE-2020-24985
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.

CVE-2020-24644
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-11803
Software Genérico Web
N/A
UNKNOWN
EPSS
8.7%
2020 2 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.