2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-2952
Hospitality Reporting and Analytics Web Database
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized

CVE-2019-10253
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.

CVE-2019-6251
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 1 PoC

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVE-2019-10864
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.

CVE-2019-10475
Jenkins build-metrics Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2019 2 PoCs

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

CVE-2019-14314
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
32.4%
2019 2 PoCs

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

CVE-2019-19456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

CVE-2019-6112
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2019 1 PoC

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

CVE-2019-19595
Software Genérico Web
N/A
UNKNOWN
EPSS
5.6%
2019 1 PoC

reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

CVE-2019-9792
Thunderbird Web
N/A
UNKNOWN
EPSS
19.0%
2019 2 PoCs

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVE-2019-15864
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.

CVE-2019-14679
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

CVE-2019-9769
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.

CVE-2019-16197
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

CVE-2019-11367
Software Genérico Web
N/A
UNKNOWN
EPSS
3.5%
2019 2 PoCs

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

CVE-2019-2763
Hospitality Gift and Loyalty Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Hospitality Gift and Loyalty component of Oracle Food and Beverage Applications. Supported versions that are affected are 9.0.0 and 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Gift and Loyalty. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Gift and Loyalty accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Gift and Loyalty accessible data

CVE-2019-10349
Jenkins Dependency Graph Viewer Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

CVE-2019-5448
yarn Web
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-311 1 PoC

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

CVE-2019-15229
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

CVE-2019-14772
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

verdaccio before 3.12.0 allows XSS.