7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-28436
google-cloudstorage-commands Cloud
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package google-cloudstorage-commands.

CVE-2020-12028
FactoryTalk View SE Web
7.3
HIGH
EPSS
29.9%
2020 CWE-264 1 PoC

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

CVE-2020-28455
markdown-it-toc General
7.3
HIGH
EPSS
0.2%
2020 1 PoC

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

CVE-2020-28471
properties-reader General
7.3
HIGH
EPSS
0.7%
2020 1 PoC

This affects the package properties-reader before 2.2.0.

CVE-2020-28426
kill-process-on-port General
7.3
HIGH
EPSS
6.9%
2020 1 PoC

All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

CVE-2020-7795
get-npm-package-version General
7.3
HIGH
EPSS
4.3%
2020 1 PoC

The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

CVE-2020-28429
geojson2kml General ⚡ nuclei
7.3
HIGH
EPSS
84.8%
2020 1 PoC

All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

CVE-2020-10627
Omnipod Insulin Management System General
7.3
HIGH
EPSS
0.1%
2020 CWE-284 1 PoC

Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

CVE-2020-28503
copy-props General
7.3
HIGH
EPSS
0.6%
2020 2 PoCs

The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.

CVE-2020-2506
🔥 KEV Helpdesk General
7.3
HIGH
EPSS
18.0%
2020 CWE-284 1 PoC

The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.

CVE-2020-26233
Git-Credential-Manager-Core Windows
7.3
HIGH
EPSS
15.6%
2020 CWE-706 2 PoCs

Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will first clone the top-level repository and then recursively clone all submodules by starting new Git processes from the top-level working directory. If a malicious git.exe executable is present in the top-level repository then this binary will be started by Git Credential Manager Core when attempting to read configuration, and not git.exe as

CVE-2020-1319
Windows 10 Version 1803 Windows
7.3
HIGH
EPSS
12.4%
2020 1 PoC

<p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>Exploitation of the vulnerability requires that a program process a specially crafted image file.</p> <p>The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory.</p>

CVE-2020-2786
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 2 PoCs

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial d

CVE-2020-2784
Outside In Technology Web Database
7.3
HIGH
EPSS
0.9%
2020 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partia

CVE-2020-28499
merge General
7.3
HIGH
EPSS
0.5%
2020 2 PoCs

All versions of package merge are vulnerable to Prototype Pollution via _recursiveMerge .

CVE-2020-12510
TwinCat XAR 3.1 General
7.3
HIGH
EPSS
0.2%
2020 CWE-276 1 PoC

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher pr

CVE-2020-28470
@scullyio/scully General
7.3
HIGH
EPSS
0.3%
2020 1 PoC

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

CVE-2020-36768
NESP2 Networking Database
7.3
HIGH
EPSS
0.1%
2020 CWE-89 1 PoC

A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.

CVE-2020-28425
curljs General
7.3
HIGH
EPSS
0.5%
2020 1 PoC

This affects all versions of package curljs.

CVE-2020-9392
Software Genérico Web Windows
7.3
HIGH
EPSS
1.0%
2020 1 PoC

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table information, create new tables, or import/modify a table.