2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-14699
Software Genérico Web
N/A
UNKNOWN
EPSS
8.5%
2019 1 PoC

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web server.

CVE-2019-3019
Banking Digital Experience Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Loan Calculator). Supported versions that are affected are 18.1, 18.2, 18.3 and 19.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Digital Experience, attacks may significantly impact additional products. Successful attacks of this vulnerability can resu

CVE-2019-10072
Apache Tomcat Web
N/A
UNKNOWN
EPSS
71.3%
2019 5 PoCs

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVE-2019-19851
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.

CVE-2019-12868
Software Genérico Web
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.

CVE-2019-17092
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 3 PoCs

An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.

CVE-2019-9673
Software Genérico Web
N/A
UNKNOWN
EPSS
15.7%
2019 1 PoC

Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

CVE-2019-17225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.

CVE-2019-16221
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
2.4%
2019 1 PoC

WordPress before 5.2.3 allows reflected XSS in the dashboard.

CVE-2019-5983
HTML5 Maps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-15037
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.

CVE-2019-13497
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

CVE-2019-8424
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

CVE-2019-11446
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2019 2 PoCs

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

CVE-2019-16956
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2019 1 PoC

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

CVE-2019-5974
Contest Gallery Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-12562
Software Genérico Web
N/A
UNKNOWN
EPSS
38.7%
2019 3 PoCs

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

CVE-2019-11374
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2019 2 PoCs

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

CVE-2019-15834
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

CVE-2019-9025
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.