2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-17573
CXF Web
N/A
UNKNOWN
EPSS
14.0%
2019 3 PoCs

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.

CVE-2019-3960
WallacePOS Web
N/A
UNKNOWN
EPSS
2.3%
2019 1 PoC

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

CVE-2019-7610
Kibana Web
N/A
UNKNOWN
EPSS
1.1%
2019 CWE-94 2 PoCs

Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

CVE-2019-9908
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 3 PoCs

The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.

CVE-2019-16118
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.6%
2019 2 PoCs

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.

CVE-2019-18952
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.7%
2019 1 PoC

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

CVE-2019-14537
Software Genérico Web
N/A
UNKNOWN
EPSS
15.0%
2019 1 PoC

YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

CVE-2019-7621
Kibana Web
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-79 1 PoC

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.

CVE-2019-13507
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

CVE-2019-20183
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
55.0%
2019 2 PoCs

uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.

CVE-2019-10874
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.

CVE-2019-14227
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

OX App Suite 7.10.1 and 7.10.2 allows XSS.

CVE-2019-3964
OpenEMR Web
N/A
UNKNOWN
EPSS
21.5%
2019 1 PoC

In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

CVE-2019-5149
WAGO PFC200 Firmware Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default configuration of this module appears to limit the number of concurrent php-cgi processes to two, which can be abused to cause a denial of service of the entire web server. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware ve

CVE-2019-3402
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2019 1 PoC

The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

CVE-2019-19598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If this value is equal to the value stored in the device's /var/hnap/timestamp file, the request will pass the HNAP_AUTH check function.

CVE-2019-20178
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.

CVE-2019-2843
FLEXCUBE Investor Servicing Web Database
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized read access to a subset

CVE-2019-20376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.