2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-13182
Software Genérico Web
N/A
UNKNOWN
EPSS
2.4%
2019 3 PoCs

A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

CVE-2019-2470
Partner Management Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Detail). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products. Successful attacks of this vulnerab

CVE-2019-10692
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.8%
2019 1 PoC

In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.

CVE-2019-15776
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.

CVE-2019-2452
WebLogic Server Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data and unauthor

CVE-2019-19612
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0.

CVE-2019-13183
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.

CVE-2019-2658
WebLogic Server Web Database
N/A
UNKNOWN
EPSS
1.7%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2019-15830
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

CVE-2019-3948
Dahua IPC-XXBXX Web
N/A
UNKNOWN
EPSS
45.3%
2019 2 PoCs

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing

CVE-2019-0192
Apache Solr Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2019 4 PoCs

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

CVE-2019-11193
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

CVE-2019-16223
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.3%
2019 3 PoCs

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVE-2019-14246
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2019 3 PoCs

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

CVE-2019-2792
Outside In Technology Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a p

CVE-2019-9881
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
32.9%
2019 3 PoCs

The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

CVE-2019-7543
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2019 0 PoCs

In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.

CVE-2019-12844
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

CVE-2019-19493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

CVE-2019-9189
Software Genérico Web
N/A
UNKNOWN
EPSS
19.4%
2019 1 PoC

Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.