2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-14774
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.

CVE-2019-14695
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2019 1 PoC

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.

CVE-2019-3943
RouterOS Web Networking
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-23 1 PoC

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).

CVE-2019-2676
CRM Technical Foundation Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerabi

CVE-2019-19634
Software Genérico Web
N/A
UNKNOWN
EPSS
15.0%
2019 3 PoCs

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

CVE-2019-0368
SAP Customer Relationship Management (Email Management - S4CRM) Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.

CVE-2019-18957
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.1%
2019 1 PoC

Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

CVE-2019-6588
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.

CVE-2019-9961
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVE-2019-2570
Siebel Core - Server Framework Web Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Vulnerability in the Siebel Core - Server BizLogic Script component of Oracle Siebel CRM (subcomponent: Integration - Scripting). The supported version that is affected is 19.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Core - Server BizLogic Script. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel Core - Server BizLogic Script accessible data as well as unauthorized read access to a subset of Siebel Core - Server BizLogic Script accessible data and unau

CVE-2019-12868
Software Genérico Web
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.

CVE-2019-17092
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 3 PoCs

An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.

CVE-2019-9673
Software Genérico Web
N/A
UNKNOWN
EPSS
15.7%
2019 1 PoC

Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

CVE-2019-5983
HTML5 Maps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-15037
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.

CVE-2019-13497
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

CVE-2019-8424
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

CVE-2019-11446
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2019 2 PoCs

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

CVE-2019-16956
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2019 1 PoC

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.