2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-20048
Software Genérico Web
N/A
UNKNOWN
EPSS
7.3%
2019 2 PoCs

An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.

CVE-2019-7262
Software Genérico Web
N/A
UNKNOWN
EPSS
39.1%
2019 1 PoC

Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

CVE-2019-2742
BI Publisher (formerly XML Publisher) Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data as well as unauthorized read access to a subset of Or

CVE-2019-19737
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.

CVE-2019-15954
Software Genérico Web
N/A
UNKNOWN
EPSS
56.9%
2019 1 PoC

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

CVE-2019-17235
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.

CVE-2019-2459
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the so

CVE-2019-20801
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

CVE-2019-9638
Software Genérico Web
N/A
UNKNOWN
EPSS
15.9%
2019 1 PoC

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.

CVE-2019-14348
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
29.0%
2019 2 PoCs

The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

CVE-2019-13954
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system. Malicious code cannot be injected.

CVE-2019-18884
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.

CVE-2019-2473
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depen

CVE-2019-9165
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.3%
2019 1 PoC

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

CVE-2019-13396
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
68.6%
2019 2 PoCs

FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

CVE-2019-2713
Commerce Merchandising Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Merchandising accessible data as well as unauthorized read access to a subset of Oracle Commerce Merchandising accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality an

CVE-2019-13386
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.

CVE-2019-15732
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

CVE-2019-2980
FLEXCUBE Direct Banking Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: eMail). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-7316
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.