2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-19266
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.

CVE-2019-1010279
Suricata Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packets. The component is: detect.c (https://github.com/OISF/suricata/pull/3625/commits/d8634daf74c882356659addb65fb142b738a186b). The attack vector is: An attacker can trigger the vulnerability by a specifically crafted network TCP session. The fixed version is: 4.1.3.

CVE-2019-16687
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

CVE-2019-6146
Forcepoint Web Security Web
N/A
UNKNOWN
EPSS
2.0%
2019 CWE-79 1 PoC

It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVE-2019-9176
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows CSRF.

CVE-2019-9591
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 2 PoCs

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.

CVE-2019-14949
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The wp-database-backup plugin before 5.1.2 for WordPress has XSS.

CVE-2019-8375
Software Genérico Web
N/A
UNKNOWN
EPSS
19.3%
2019 2 PoCs

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

CVE-2019-12517
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality available via the /wp-admin/admin-ajax.php endpoint allows unauthenticated users to submit quiz solutions/answers, which are stored in the database and later shown in the WordPress backend for all users with at least Subscriber rights. Because the plugin does not properly validate and sanitize this data, a malicious payload in either the name or email field is executed directly within the backend at /wp-admin/admin.php?page=slickquiz across all users with the privileges of at le

CVE-2019-10658
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.

CVE-2019-5480
statichttpserver Web
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-22 1 PoC

A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.

CVE-2019-10677
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
5.5%
2019 3 PoCs

Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).

CVE-2019-13234
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

CVE-2019-5160
WAGO PFC200 Firmware Web Cloud
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.

CVE-2019-19823
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
28.7%
2019 3 PoCs

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-1

CVE-2019-13376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

CVE-2019-14205
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2019 2 PoCs

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-12543
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.