2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-10383
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.

CVE-2019-20354
Software Genérico Web
N/A
UNKNOWN
EPSS
21.2%
2019 1 PoC

The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

CVE-2019-6780
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
3.6%
2019 1 PoC

The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.

CVE-2019-10756
node-red-dashboard Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.

CVE-2019-15934
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Intesync Solismed 3.3sp has CSRF.

CVE-2019-17571
Log4j Web
N/A
UNKNOWN
EPSS
37.0%
2019 CWE-502 9 PoCs

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

CVE-2019-1563
OpenSSL Web Database
N/A
UNKNOWN
EPSS
1.3%
2019 8 PoCs

In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not affected if they use a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c)

CVE-2019-7419
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title.

CVE-2019-9024
Software Genérico Web
N/A
UNKNOWN
EPSS
13.7%
2019 2 PoCs

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.

CVE-2019-11604
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 3 PoCs

An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web application. Since the application does not properly validate and sanitize this parameter, it is possible to place arbitrary script code into the context of the same page.

CVE-2019-1010207
Pie Register Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.

CVE-2019-1551
OpenSSL Web
N/A
UNKNOWN
EPSS
2.4%
2019 6 PoCs

There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in

CVE-2019-17214
Software Genérico Web Networking Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.

CVE-2019-9084
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /tab_tariffe.php?anno=[YEAR]&numtariffa1=1a URI. It could allow an administrator to conduct remote denial of service (disrupting certain business functions of the product).

CVE-2019-2771
BI Publisher (formerly XML Publisher) Web Database
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability

CVE-2019-2673
Marketing Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: Marketing Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result

CVE-2019-16693
Software Genérico Web Database
N/A
UNKNOWN
EPSS
15.9%
2019 1 PoC

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

CVE-2019-17001
Firefox Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.

CVE-2019-16950
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.

CVE-2019-16070
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a threat actor to inject malicious code directly into the application through web application form inputs.