2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-9740
Software Genérico Web Database
N/A
UNKNOWN
EPSS
9.9%
2019 5 PoCs

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.

CVE-2019-14681
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.

CVE-2019-8387
Software Genérico Web
N/A
UNKNOWN
EPSS
67.5%
2019 2 PoCs

MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

CVE-2019-3403
Jira Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.8%
2019 CWE-863 1 PoC

The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVE-2019-17181
Software Genérico Web
N/A
UNKNOWN
EPSS
74.1%
2019 1 PoC

A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can result in a compromise of the hosting system.

CVE-2019-19852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.

CVE-2019-7418
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc.

CVE-2019-15831
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.

CVE-2019-6514
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.

CVE-2019-13635
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.2%
2019 2 PoCs

The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.

CVE-2019-2772
PeopleSoft Enterprise PT PeopleTools Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Activity Guide). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unautho

CVE-2019-14231
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
6.6%
2019 2 PoCs

An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.

CVE-2019-1010257
article2pdf Wordpress plug-in Web Windows
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. A URL can be constructed which allows overriding the PDF file's path leading to any PDF whose path is known and which is readable to the web server can be downloaded. The file will be deleted after download if the web server has permission to do so. For PHP versions before 5.3, any file can be read by null terminating the string left of the file extension.

CVE-2019-1000003
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via the victim must be logged in to WordPress as an admin, and click a link. This vulnerability appears to have been fixed in 3.3.0 and later.

CVE-2019-3919
Alcatel Lucent I-240W-Q GPON ONT Web
N/A
UNKNOWN
EPSS
10.2%
2019 CWE-78 1 PoC

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/usb_restore_Form?script/.

CVE-2019-3001
PeopleSoft Enterprise SCM eProcurement Web Database
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eProcurement. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise SCM eProcurement accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-2399
Communications Diameter Signaling Router (DSR) Web Networking Database Cloud
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) component of Oracle Communications Applications (subcomponent: Security). The supported version that is affected is prior to 8.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data and unauthorized ability to cause a partial denial of service (part

CVE-2019-9879
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
76.2%
2019 3 PoCs

The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

CVE-2019-15775
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVE-2019-11846
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.