2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-16932
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2019 2 PoCs

A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.

CVE-2019-16523
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 2 PoCs

The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.

CVE-2019-17563
Apache Tomcat Web
N/A
UNKNOWN
EPSS
4.4%
2019 4 PoCs

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

CVE-2019-10866
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
13.5%
2019 2 PoCs

In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

CVE-2019-6706
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2019 2 PoCs

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

CVE-2019-2463
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside I

CVE-2019-12541
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

CVE-2019-5430
UniFi Video Server Web
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-352 1 PoC

In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.

CVE-2019-12592
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFrame.

CVE-2019-12102
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

Kentico 11 through 12 lets attackers upload and explore files without authentication via the cmsmodules/medialibrary/formcontrols/liveselectors/insertimageormedia/tabs_media.aspx URI. NOTE: The vendor disputes the report because the researcher did not configure the media library permissions correctly. The vendor states that by default all users can read/modify/upload files, and it’s up to the administrator to decide who should have access to the media library and set the permissions accordingly. See the vendor documentation in the references for more information

CVE-2019-15645
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

CVE-2019-20887
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.

CVE-2019-15830
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

CVE-2019-3948
Dahua IPC-XXBXX Web
N/A
UNKNOWN
EPSS
45.3%
2019 2 PoCs

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing

CVE-2019-0192
Apache Solr Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2019 4 PoCs

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

CVE-2019-11193
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

CVE-2019-16223
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.3%
2019 3 PoCs

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVE-2019-14246
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2019 3 PoCs

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

CVE-2019-2792
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a p

CVE-2019-9881
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2019 3 PoCs

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.