7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7065
PHP Web
7.4
HIGH
EPSS
5.0%
2020 CWE-121 1 PoC

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVE-2020-7278
McAfee Endpoint Security (ENS) Networking Windows
7.4
HIGH
EPSS
0.2%
2020 CWE-284 1 PoC

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.

CVE-2020-4958
Security Identity Governance and Intelligence General
7.4
HIGH
EPSS
0.3%
2020 1 PoC

IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. IBM X-Force ID: 192209.

CVE-2020-14593
Java Database
7.4
HIGH
EPSS
0.4%
2020 2 PoCs

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in

CVE-2020-25638
hibernate-core Web Database
7.4
HIGH
EPSS
0.7%
2020 CWE-89 4 PoCs

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-2739
WebCenter Sites Web Database
7.4
HIGH
EPSS
3.2%
2020 1 PoC

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to

CVE-2020-16991
Azure Sphere Cloud
7.3
HIGH
EPSS
0.3%
2020 1 PoC

Azure Sphere Unsigned Code Execution Vulnerability

CVE-2020-13285
GitLab DevOps Web
7.3
HIGH
EPSS
0.1%
2020 1 PoC

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

CVE-2020-28895
Software Genérico General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.

CVE-2020-7766
json-ptr Web
7.3
HIGH
EPSS
1.1%
2020 4 PoCs

This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.

CVE-2020-28472
@aws-sdk/shared-ini-file-loader Cloud
7.3
HIGH
EPSS
1.7%
2020 4 PoCs

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-7788
ini General
7.3
HIGH
EPSS
0.3%
2020 2 PoCs

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-6293
SAP NetWeaver (Knowledge Management) General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limited to the files themselves and is restricted by other policies such as access control lists and other upload file size restrictions, leading to Unrestricted File Upload.

CVE-2020-28461
js-ini General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-2787
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d

CVE-2020-14543
Hospitality Reporting and Analytics Database
7.3
HIGH
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVS

CVE-2020-28433
node-latex-pdf General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package node-latex-pdf.

CVE-2020-36541
Demokratian Web Database
7.3
HIGH
EPSS
0.3%
2020 CWE-89 3 PoCs

A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown functionality of the file basicos_php/genera_select.php. The manipulation of the argument id_provincia with the input -1%20union%20all%20select%201,2,3,4,database() leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2020-7351
Trixbox Community Edition Web
7.3
HIGH
EPSS
68.9%
2020 CWE-78 1 PoC

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.