2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-14221
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

CVE-2019-9841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.

CVE-2019-5979
Personalized WooCommerce Cart Page Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-9020
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 2 PoCs

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

CVE-2019-15864
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.

CVE-2019-9041
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
88.2%
2019 1 PoC

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

CVE-2019-2763
Hospitality Gift and Loyalty Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the Oracle Hospitality Gift and Loyalty component of Oracle Food and Beverage Applications. Supported versions that are affected are 9.0.0 and 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Gift and Loyalty. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Gift and Loyalty accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality Gift and Loyalty accessible data

CVE-2019-11073
Software Genérico Web
N/A
UNKNOWN
EPSS
12.7%
2019 1 PoC

A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Transaction Sensor and set specific settings when the sensor is executed.

CVE-2019-10349
Jenkins Dependency Graph Viewer Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

CVE-2019-13768
Chrome Web
N/A
UNKNOWN
EPSS
1.6%
2019 2 PoCs

Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

CVE-2019-13764
Chrome Web
N/A
UNKNOWN
EPSS
39.5%
2019 1 PoC

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-16251
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

CVE-2019-16107
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.

CVE-2019-2414
HTTP Server Web Database
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2019-1010104
Quick Chat WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.

CVE-2019-2573
PeopleSoft Enterprise PT PeopleTools Web Database
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base S

CVE-2019-14756
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.

CVE-2019-19211
Software Genérico Web
N/A
UNKNOWN
EPSS
2.1%
2019 2 PoCs

Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.

CVE-2019-10092
Apache HTTP Server Web ⚡ nuclei
N/A
UNKNOWN
EPSS
82.4%
2019 7 PoCs

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.