2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-19265
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.

CVE-2019-10081
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
24.0%
2019 4 PoCs

HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client.

CVE-2019-2903
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partia

CVE-2019-5489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 4 PoCs

The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.

CVE-2019-2935
Siebel UI Framework Web Database
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-17233
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

CVE-2019-9055
Software Genérico Web
N/A
UNKNOWN
EPSS
32.0%
2019 1 PoC

An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

CVE-2019-5479
larvitbase-api Web
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-98 2 PoCs

An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).

CVE-2019-14950
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 0 PoCs

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

CVE-2019-9592
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 2 PoCs

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVE-2019-18653
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

CVE-2019-2496
CRM Technical Foundation Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerabilit

CVE-2019-10708
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.4%
2019 1 PoC

S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.

CVE-2019-2883
Retail Customer Management and Segmentation Foundation Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). The supported version that is affected is 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Customer Management and Segmen

CVE-2019-2608
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to

CVE-2019-19016
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.

CVE-2019-12180
Software Genérico Web
N/A
UNKNOWN
EPSS
8.6%
2019 2 PoCs

An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious Project. The same issue is present in the "Save Script" function, which is executed automatically when saving a project.

CVE-2019-12148
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.

CVE-2019-12195
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.

CVE-2019-14947
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.