7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10499
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.

CVE-2020-35717
Software Genérico Web
N/A
UNKNOWN
EPSS
6.1%
2020 4 PoCs

zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

CVE-2020-13829
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).

CVE-2020-10851
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).

CVE-2020-15468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.

CVE-2020-25217
Software Genérico General
N/A
UNKNOWN
EPSS
3.1%
2020 2 PoCs

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.

CVE-2020-5809
Umbraco CMS Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in Umbraco CMS.

CVE-2020-14387
rsync General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-297 1 PoC

A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.

CVE-2020-0537
Intel(R) AMT General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

CVE-2020-24985
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.

CVE-2020-24644
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-11803
Software Genérico Web
N/A
UNKNOWN
EPSS
8.7%
2020 2 PoCs

An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.

CVE-2020-9459
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings.

CVE-2020-7644
fun-map General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

CVE-2020-11524
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

CVE-2020-23051
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.

CVE-2020-1904
WhatsApp for iOS General
N/A
UNKNOWN
EPSS
0.5%
2020 CWE-23 1 PoC

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

CVE-2020-16040
Chrome General
N/A
UNKNOWN
EPSS
75.1%
2020 3 PoCs

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15368
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2020 3 PoCs

AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.

CVE-2020-11609
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 3 PoCs

An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka CID-485b06aadb93.