2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-13401
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.

CVE-2019-15478
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Status Board 1.1.81 has reflected XSS via logic.ts.

CVE-2019-18802
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

CVE-2019-20401
Jira Server Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.

CVE-2019-19945
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2019 2 PoCs

uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.

CVE-2019-12415
Apache POI Web
N/A
UNKNOWN
EPSS
0.0%
2019 8 PoCs

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.

CVE-2019-20174
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

CVE-2019-2841
FLEXCUBE Investor Servicing Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data as well as unauthorized

CVE-2019-6967
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.

CVE-2019-11593
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

CVE-2019-10384
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

CVE-2019-11715
Firefox ESR Web
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVE-2019-6515
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthenticated user.

CVE-2019-20375
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.

CVE-2019-14343
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 3 PoCs

TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.

CVE-2019-2594
PeopleSoft Enterprise PT PeopleTools Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.55, 8.56 and 8.57. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to

CVE-2019-0374
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title resulting in reflected Cross-Site Scripting

CVE-2019-11517
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.

CVE-2019-2674
One-to-One Fulfillment Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of thi