2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-14223
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.3%
2019 1 PoC

An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

CVE-2019-1000031
article2pdf Wordpress plug-in Web Windows
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in.

CVE-2019-7435
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.

CVE-2019-12954
Software Genérico Web
N/A
UNKNOWN
EPSS
2.9%
2019 1 PoC

SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.

CVE-2019-20921
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser.

CVE-2019-16679
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.

CVE-2019-11504
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

Zotonic before version 0.47 has mod_admin XSS.

CVE-2019-12185
Software Genérico Web
N/A
UNKNOWN
EPSS
26.4%
2019 1 PoC

eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

CVE-2019-17236
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.

CVE-2019-17543
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

CVE-2019-17270
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.9%
2019 2 PoCs

Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVE-2019-0363
SAP HANA Extended Application Services Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports.

CVE-2019-14221
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

CVE-2019-5979
Personalized WooCommerce Cart Page Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-9020
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 2 PoCs

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

CVE-2019-13768
Chrome Web
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2019-13764
Chrome Web
N/A
UNKNOWN
EPSS
39.5%
2019 1 PoC

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-16251
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.