7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37028
Photo to Video Converter Professional General
8.4
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder' input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the output folder field to trigger a stack-based buffer overflow and potentially execute shellcode.

CVE-2020-36961
Network Inventory Explorer General
8.4
HIGH
EPSS
0.3%
2020 CWE-121 1 PoC

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code execution.

CVE-2020-26910
Software Genérico General
8.4
HIGH
EPSS
0.3%
2020 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

CVE-2020-16875
Microsoft Exchange Server 2019 Cumulative Update 5 Windows
8.4
HIGH
EPSS
86.8%
2020 1 PoC

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>

CVE-2020-29032
GateManager General
8.4
HIGH
EPSS
0.2%
2020 CWE-494 2 PoCs

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

CVE-2020-37126
Free Desktop Clock General
8.4
HIGH
EPSS
0.0%
2020 CWE-121 1 PoC

Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Handler (SEH) registers. Attackers can exploit the vulnerability by crafting a malicious Unicode input that triggers an access violation and potentially execute arbitrary code.

CVE-2020-37184
Allok Video Converter General
8.4
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious bytecode into the input field.

CVE-2020-37049
Frigate 3 Professional General
8.4
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload to overflow the buffer, bypass DEP, and execute commands like launching calc.exe through a specially crafted input sequence.

CVE-2020-11237
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile General
8.4
HIGH
EPSS
0.0%
2020 1 PoC

Memory crash when accessing histogram type KPI input received due to lack of check of histogram definition before accessing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVE-2020-7688
mversion General
8.4
HIGH
EPSS
0.2%
2020 1 PoC

The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.

CVE-2020-17144
🔥 KEV Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 Windows
8.4
HIGH
EPSS
92.0%
2020 2 PoCs

Microsoft Exchange Remote Code Execution Vulnerability

CVE-2020-37138
Network Inventory Explorer General
8.4
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass data execution prevention through a ROP chain.

CVE-2020-37074
Remote Desktop Audit General
8.4
HIGH
EPSS
0.1%
2020 CWE-120 1 PoC

Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer lists.

CVE-2020-11242
Snapdragon Industrial IOT, Snapdragon Mobile Web
8.4
HIGH
EPSS
0.0%
2020 1 PoC

User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-37161
Wedding Slideshow Studio General
8.4
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can craft a specially designed payload to trigger remote code execution, demonstrating the ability to run system commands like launching the calculator.

CVE-2020-37142
Network Inventory Explorer General
8.4
HIGH
EPSS
0.0%
2020 CWE-121 2 PoCs

10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger remote code execution.

CVE-2020-37013
Audio Playback Recorder General
8.4
HIGH
EPSS
0.0%
2020 CWE-121 2 PoCs

Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters that allows attackers to execute arbitrary code. Attackers can craft malicious payloads and overwrite Structured Exception Handler (SEH) to execute shellcode when pasting specially crafted input into the application's input fields.

CVE-2020-11234
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
8.4
HIGH
EPSS
0.0%
2020 1 PoC

When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-37001
Frigate Professional General
8.4
HIGH
EPSS
0.0%
2020 CWE-121 1 PoC

Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.

CVE-2020-11246
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
8.4
HIGH
EPSS
0.0%
2020 1 PoC

A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile