2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-18839
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

CVE-2019-10072
Apache Tomcat Web
N/A
UNKNOWN
EPSS
71.3%
2019 5 PoCs

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVE-2019-2700
PeopleSoft Enterprise ELM Enterprise Learning Management Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

CVE-2019-17225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.

CVE-2019-16221
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.4%
2019 1 PoC

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVE-2019-10076
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.0%
2019 1 PoC

A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

CVE-2019-2833
Hospitality Simphony Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vulnerability in the Oracle Hospitality Simphony component of Oracle Food and Beverage Applications. The supported version that is affected is 18.2.1. Easily exploitable vulnerability allows low privileged attacker having Import/Export privilege with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Simphony accessible data. CVSS 3

CVE-2019-7232
Software Genérico Web
N/A
UNKNOWN
EPSS
7.4%
2019 2 PoCs

The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unauthenticated attacker can submit a Host header value of 2047 bytes or more to overflow the buffer and overwrite the SEH address, which can then be leveraged to execute attacker-controlled code on the server.

CVE-2019-19542
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.

CVE-2019-8391
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2019 2 PoCs

qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.

CVE-2019-10078
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.0%
2019 2 PoCs

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

CVE-2019-14913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel.

CVE-2019-10090
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
4.4%
2019 1 PoC

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

CVE-2019-9844
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.

CVE-2019-16869
Software Genérico Web
N/A
UNKNOWN
EPSS
15.0%
2019 1 PoC

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

CVE-2019-7423
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2019 2 PoCs

XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.

CVE-2019-11871
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

CVE-2019-20504
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.8%
2019 0 PoCs

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.

CVE-2019-16534
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.