2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-17560
Apache NetBeans Web
N/A
UNKNOWN
EPSS
1.6%
2019 1 PoC

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

CVE-2019-19553
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.

CVE-2019-14470
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.6%
2019 3 PoCs

cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.

CVE-2019-12725
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2019 11 PoCs

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

CVE-2019-2964
Java Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified

CVE-2019-17218
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service.

CVE-2019-0377
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the input controls, resulting in Stored Cross-Site Scripting.

CVE-2019-17515
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.

CVE-2019-13392
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.9%
2019 0 PoCs

A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect the recipient value if it is not in the NateMail recipient array. Note that this array is keyed via integers by default, so any string input will be invalid.

CVE-2019-12453
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

CVE-2019-10310
Jenkins Ansible Tower Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins