2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-5974
Contest Gallery Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-12562
Software Genérico Web
N/A
UNKNOWN
EPSS
38.7%
2019 3 PoCs

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

CVE-2019-19033
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.

CVE-2019-14430
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

CVE-2019-3994
ELOG Web
N/A
UNKNOWN
EPSS
2.8%
2019 CWE-416 1 PoC

ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable.

CVE-2019-2704
Solaris Operating System Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: IPS Package Manager). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-14656
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVE-2019-7219
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2019 1 PoC

Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

CVE-2019-17237
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.

CVE-2019-16113
Software Genérico Web
N/A
UNKNOWN
EPSS
89.0%
2019 18 PoCs

Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.

CVE-2019-2742
BI Publisher (formerly XML Publisher) Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data as well as unauthorized read access to a subset of Or

CVE-2019-11374
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2019 2 PoCs

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

CVE-2019-15834
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

CVE-2019-9025
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.

CVE-2019-2567
Configurator Web Database
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

Vulnerability in the Oracle Configurator component of Oracle Supply Chain Products Suite (subcomponent: Active Model Generation). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-14696
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
32.6%
2019 1 PoC

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2019-8428
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.

CVE-2019-8390
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2019 2 PoCs

qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.

CVE-2019-20921
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.

CVE-2019-16679
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.