2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-5480
statichttpserver Web
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-22 1 PoC

A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.

CVE-2019-11410
Software Genérico Web
N/A
UNKNOWN
EPSS
9.8%
2019 1 PoC

app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.

CVE-2019-2709
Transportation Management Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.3.7, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unaut

CVE-2019-3966
OpenEMR Web
N/A
UNKNOWN
EPSS
28.9%
2019 1 PoC

In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

CVE-2019-10677
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
5.5%
2019 3 PoCs

Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).

CVE-2019-13234
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

CVE-2019-5160
WAGO PFC200 Firmware Web Cloud
N/A
UNKNOWN
EPSS
2.2%
2019 1 PoC

An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.

CVE-2019-19823
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
28.7%
2019 3 PoCs

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-1

CVE-2019-13376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

CVE-2019-14205
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2019 2 PoCs

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

CVE-2019-2417
PeopleSoft Enterprise PT PeopleTools Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.

CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-12543
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

CVE-2019-17563
Apache Tomcat Web
N/A
UNKNOWN
EPSS
4.4%
2019 4 PoCs

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

CVE-2019-10866
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
13.5%
2019 2 PoCs

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

CVE-2019-15837
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The webp-express plugin before 0.14.8 for WordPress has stored XSS.

CVE-2019-2615
WebLogic Server Web Database
N/A
UNKNOWN
EPSS
58.3%
2019 2 PoCs

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-10232
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
85.9%
2019 0 PoCs

Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

CVE-2019-5963
Zoho SalesIQ Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-7429
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory.