3091 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2019-5187
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2019-9670
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2019 4 PoCs

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

CVE-2019-9884
eclass General
9.8
CRITICAL
EPSS
0.4%
2019 CWE-284 1 PoC

eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

CVE-2019-13658
CA Network Flow Analysis General
9.8
CRITICAL
EPSS
1.3%
2019 CWE-798 1 PoC

CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

CVE-2019-7192
🔥 KEV QNAP NAS devices running Photo Station General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2019 3 PoCs

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

CVE-2019-3396
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2019 26 PoCs

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CVE-2019-5132
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A specially crafted GEM file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2019-17444
Artifactory General ⚡ nuclei
9.8
CRITICAL
EPSS
92.5%
2019 CWE-521 2 PoCs

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

CVE-2019-9201
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2019 1 PoC

Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.

CVE-2019-10160
python General
9.8
CRITICAL
EPSS
1.5%
2019 CWE-172 1 PoC

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a diffe

CVE-2019-19006
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
21.6%
2019 3 PoCs

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

CVE-2019-13657
CA Performance Management General
9.8
CRITICAL
EPSS
0.5%
2019 CWE-798 2 PoCs

CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

CVE-2019-11580
🔥 KEV Crowd General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2019 3 PoCs

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x),

CVE-2019-20695
Software Genérico General
9.4
CRITICAL
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects SRK60 before 2.3.5.106, SRR60 before 2.3.5.106, and SRS60 before 2.3.5.106.

CVE-2019-25441
thesystem General
9.3
CRITICAL
EPSS
6.2%
2019 CWE-78 1 PoC

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.

CVE-2019-25714
A8-V5 Collaborative Management Software General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-434 1 PoC

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).

CVE-2019-25568
Memu Play General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-306 1 PoC

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

CVE-2019-25322
Heatmiser Netmonitor General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-798 1 PoC

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

CVE-2019-25291
Smartliving SmartLAN/G/SI General
9.3
CRITICAL
EPSS
0.1%
2019 CWE-798 2 PoCs

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.

CVE-2019-25614
Free Float FTP General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-787 1 PoC

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.