2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-12094
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2019 4 PoCs

Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.

CVE-2019-20213
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.8%
2019 4 PoCs

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.

CVE-2019-2441
WebLogic Server DevOps Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-15865
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.

CVE-2019-17116
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is created. The malicious script is stored and will be executed again whenever /WiKIDAdmin/groups.jsp is visited.

CVE-2019-5471
GitLab DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-79 1 PoC

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

CVE-2019-16117
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.

CVE-2019-13571
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
5.1%
2019 3 PoCs

A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

CVE-2019-6973
Software Genérico Web
N/A
UNKNOWN
EPSS
12.5%
2019 2 PoCs

Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

CVE-2019-20803
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme.

CVE-2019-0190
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
18.9%
2019 3 PoCs

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.

CVE-2019-17566
Apache Batik Web
N/A
UNKNOWN
EPSS
0.8%
2019 6 PoCs

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVE-2019-19908
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
41.9%
2019 1 PoC

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

CVE-2019-5920
FormCraft Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.

CVE-2019-10867
Software Genérico Web
N/A
UNKNOWN
EPSS
52.7%
2019 3 PoCs

An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.

CVE-2019-17405
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Nokia IMPACT < 18A: has Reflected self XSS

CVE-2019-9039
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication and external access to this REST endpoint has been blocked to mitigate this issue. This issue has been f

CVE-2019-16958
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.

CVE-2019-10633
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to execute arbitrary code via the tjp6jp6y4, simZysh, and ck6fup6 APIs.

CVE-2019-2941
Hyperion Profitability and Cost Management Web Database
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Vulnerability in the Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Modeling). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Profitability and Cost Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Profitability and Cost Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthoriz