2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-9539
Automated Message Handling System Web
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-79 1 PoC

: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

CVE-2019-13070
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Recipient page, the embedded code will be executed in the browser of the victim.

CVE-2019-9553
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2019 2 PoCs

Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

CVE-2019-15838
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.

CVE-2019-16250
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

CVE-2019-16744
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

eBrigade before 5.0 has evenements.php cid SQL Injection.

CVE-2019-2936
Hospitality Reporting and Analytics Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows low privileged attacker having Admin - Configuration privilege with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized access to critical data or

CVE-2019-15644
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.

CVE-2019-2583
iSupplier Portal Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle iSupplier Portal component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iSupplier Portal, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unaut

CVE-2019-20182
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.

CVE-2019-16743
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.

CVE-2019-16220
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.

CVE-2019-8927
Software Genérico Web
N/A
UNKNOWN
EPSS
2.5%
2019 3 PoCs

An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource, selectDeviceDone, task, val10, and val11.

CVE-2019-20858
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.

CVE-2019-10754
Apereo CAS Web
N/A
UNKNOWN
EPSS
0.4%
2019 5 PoCs

Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID generation which makes them predictable due to RandomStringUtils PRNG's algorithm not being cryptographically strong.

CVE-2019-9194
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2019 3 PoCs

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

CVE-2019-15895
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

CVE-2019-19946
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

CVE-2019-2467
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depen

CVE-2019-9581
Software Genérico Web
N/A
UNKNOWN
EPSS
17.0%
2019 3 PoCs

phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.