7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36888
Fusion Digital Signage General
6.9
MEDIUM
EPSS
0.0%
2020 CWE-203 2 PoCs

SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses.

CVE-2020-37156
BloodX Web
6.9
MEDIUM
EPSS
0.1%
2020 CWE-288 1 PoC

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access.

CVE-2020-37056
http-protection Web
6.9
MEDIUM
EPSS
0.0%
2020 CWE-290 1 PoC

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.

CVE-2020-11022
jQuery General
6.9
MEDIUM
EPSS
2.5%
2020 CWE-79 17 PoCs

In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

CVE-2020-36886
Fusion Digital Signage Web
6.9
MEDIUM
EPSS
0.1%
2020 CWE-352 2 PoCs

SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.

CVE-2020-8496
Software Genérico Web
6.9
MEDIUM
EPSS
0.3%
2020 1 PoC

In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.

CVE-2020-37077
Booked Scheduler Web
6.9
MEDIUM
EPSS
0.2%
2020 CWE-22 1 PoC

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

CVE-2020-36923
Sony BRAVIA Digital Signage General
6.9
MEDIUM
EPSS
0.2%
2020 CWE-639 1 PoC

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

CVE-2020-36926
SmarterTools SmarterTrack General
6.9
MEDIUM
EPSS
0.1%
2020 CWE-497 1 PoC

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.

CVE-2020-36970
PMB Services Web
6.9
MEDIUM
EPSS
0.0%
2020 CWE-22 1 PoC

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.

CVE-2020-36884
BrightSign Digital Signage Diagnostic Web Server Web Networking
6.9
MEDIUM
EPSS
0.1%
2020 CWE-918 2 PoCs

BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts.

CVE-2020-37127
dnsmasq-utils General
6.9
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.

CVE-2020-36944
ILIAS Learning Management System Web
6.9
MEDIUM
EPSS
0.0%
2020 CWE-918 1 PoC

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PDF.

CVE-2020-1034
Windows 10 Version 1803 Windows
6.8
MEDIUM
EPSS
17.0%
2020 3 PoCs

<p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.</p> <p>The security update addresses the vulnerability by ensuring the Windows Kernel properly handles objects in memory.</p>

CVE-2020-4497
Spectrum Protect Plus General
6.8
MEDIUM
EPSS
0.1%
2020 CWE-319 1 PoC

IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106.

CVE-2020-14552
WebCenter Portal Web Database
6.8
MEDIUM
EPSS
0.6%
2020 1 PoC

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to

CVE-2020-29506
Dell BSAFE Crypto-C Micro Edition General
6.8
MEDIUM
EPSS
1.5%
2020 CWE-385 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-14557
WebLogic Server DevOps Web Database
6.8
MEDIUM
EPSS
1.9%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well a

CVE-2020-11915
Software Genérico General
6.8
MEDIUM
EPSS
0.3%
2020 2 PoCs

An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can then be used to obtain access to the device with root privileges via a reecam4debug default password. This default telnet password is the same across all Siime Eye devices. In order for the attack to be exploited, an attacker must be physically close in order to connect to the device's Wi-Fi access point.

CVE-2020-26298
redcarpet Web
6.8
MEDIUM
EPSS
0.3%
2020 CWE-74 1 PoC

Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.