2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-25294
html5_snmp Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the page is loaded.

CVE-2019-25380
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters. Attackers can submit POST requests to dhcp.cgi with script payloads in parameters such as BOOT_SERVER, BOOT_FILE, BOOT_ROOT, START_ADDR, END_ADDR, DNS1, DNS2, NTP1, NTP2, WINS1, WINS2, DEFAULT_LEASE_TIME, MAX_LEASE_TIME, DOMAIN_NAME, NIS_DOMAIN, NIS1, NIS2, STATIC_HOST, STATIC_DESC, STATIC_MAC, and STATIC_IP to execute arbitrary JavaScript in user browsers.

CVE-2019-25313
FlexNet Publisher Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-352 1 PoC

FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.

CVE-2019-25265
Online Inventory Manager Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.

CVE-2019-25244
Legrand BTicino Driver Manager F454 Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 3 PoCs

Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET parameters.

CVE-2019-25445
Fiverr Clone Script Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Fiverr Clone Script 1.2.2 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft URLs with script tags in the keyword parameter of search-results.php to execute arbitrary JavaScript in users' browsers.

CVE-2019-25324
RICOH Web Image Monitor Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allows attackers to inject malicious HTML code. Attackers can exploit the entryNameIn and entryDisplayNameIn parameters to insert arbitrary HTML content, potentially enabling cross-site scripting attacks.

CVE-2019-25423
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the /korugan/proxyconfig endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted POST requests with JavaScript payloads in parameters like PROXY_PORT, VISIBLE_HOSTNAME, ADMIN_MAIL_ADDRESS, CACHE_MEM, MAX_SIZE, MIN_SIZE, and DST_NOCACHE to execute arbitrary scripts in administrator browsers.

CVE-2019-25415
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the hotspot_permanent_users endpoint. Attackers can send POST requests with JavaScript payloads in the MACADDRESSES parameter to execute arbitrary scripts in users' browsers.

CVE-2019-25384
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the EXT, SRC_PORT_SEL, SRC_PORT, DEST_IP, DEST_PORT_SEL, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.

CVE-2019-25316
GOautodial Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaScript in victim browsers.

CVE-2019-25234
SmartHouse Webapp Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 2 PoCs

SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.

CVE-2019-25421
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application.

CVE-2019-25238
SOL GPON/EPON OLT Platform Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-352 2 PoCs

V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to create admin users, enable SSH, or modify system settings by tricking authenticated administrators into loading a specially crafted page.

CVE-2019-25403
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the comment parameter. Attackers can inject JavaScript code through the admin_profiles endpoint that executes in the browsers of other users who view the affected page.

CVE-2019-25408
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the netmask_addr parameter. Attackers can send POST requests to the netwizard2 endpoint with script payloads in the netmask_addr parameter to execute arbitrary JavaScript in users' browsers.

CVE-2019-25270
SOCA Access Control System Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logged_page.php that allows attackers to inject malicious scripts. Attackers can exploit this weakness by sending crafted POST requests to execute arbitrary HTML and script code in a victim's browser session.

CVE-2019-25399
IPFire Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

IPFire 2.21 Core Update 127 contains multiple stored cross-site scripting vulnerabilities in the extrahd.cgi script that allow attackers to inject malicious scripts through the FS, PATH, and UUID parameters. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.

CVE-2019-4444
API Connect Web
5.1
MEDIUM
EPSS
0.1%
2019 1 PoC

IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.

CVE-2019-25356
MP-4200 Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a cross-site scripting vulnerability in the admin configuration page. Attackers can inject malicious scripts via crafted POST requests with malformed 'admin' and 'person' parameters, allowing execution of arbitrary JavaScript in the context of an authenticated user's browser session.