2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-13497
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
1.2%
2019 1 PoC

One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

CVE-2019-8424
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

CVE-2019-11446
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2019 2 PoCs

An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

CVE-2019-16956
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2019 1 PoC

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

CVE-2019-5974
Contest Gallery Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-12562
Software Genérico Web
N/A
UNKNOWN
EPSS
38.7%
2019 3 PoCs

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

CVE-2019-14791
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.

CVE-2019-11871
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

CVE-2019-16534
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.

CVE-2019-16173
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 3 PoCs

LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,

CVE-2019-15833
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.

CVE-2019-9083
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.

CVE-2019-13294
Software Genérico Web
N/A
UNKNOWN
EPSS
34.1%
2019 2 PoCs

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

CVE-2019-11374
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2019 2 PoCs

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

CVE-2019-15834
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

CVE-2019-9025
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.

CVE-2019-2567
Configurator Web Database
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: Active Model Generation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-14696
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.6%
2019 1 PoC

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2019-8428
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.

CVE-2019-8390
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2019 2 PoCs

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.