2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-13569
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.7%
2019 1 PoC

A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

CVE-2019-11846
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.

CVE-2019-7437
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.

CVE-2019-0235
Apache OFBiz Web
N/A
UNKNOWN
EPSS
4.7%
2019 1 PoC

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

CVE-2019-0207
Apache Tapestry Web Windows
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.

CVE-2019-9166
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.

CVE-2019-3922
Alcatel Lucent I-240W-Q GPON ONT Web
N/A
UNKNOWN
EPSS
12.6%
2019 CWE-121 1 PoC

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code.

CVE-2019-9167
Software Genérico Web
N/A
UNKNOWN
EPSS
13.6%
2019 1 PoC

Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.

CVE-2019-2777
Siebel Core - Server Framework Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Search). Supported versions that are affected are 19.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core - Server Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete

CVE-2019-9914
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

CVE-2019-15766
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2019 1 PoC

The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler with the configFile parameter set to the arbitrary file to be written to (and the config_text parameter set to the content of the file to be created). This can be a PHP file that is written to in the public web directory and subsequently executed. The attacker must have network connectivity to the PHP server that is running on the Android device.

CVE-2019-14427
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.

CVE-2019-12962
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2019 1 PoC

LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.

CVE-2019-15029
Software Genérico Web
N/A
UNKNOWN
EPSS
21.1%
2019 1 PoC

FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request with the service id followed by the parameter a=start to execute the stored command.

CVE-2019-0196
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
8.6%
2019 4 PoCs

A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.

CVE-2019-16532
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.

CVE-2019-11730
Firefox ESR Web
N/A
UNKNOWN
EPSS
19.4%
2019 3 PoCs

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments

CVE-2019-13072
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.

CVE-2019-14211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validation of the existence of an object prior to performing operations on that object when executing JavaScript.

CVE-2019-7324
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.