2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-14246
Software Genérico Web
N/A
UNKNOWN
EPSS
1.5%
2019 3 PoCs

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

CVE-2019-2492
Email Center Web Database
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result

CVE-2019-19210
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

CVE-2019-14328
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

CVE-2019-10077
Apache JSPWiki Web
N/A
UNKNOWN
EPSS
3.0%
2019 3 PoCs

A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

CVE-2019-17228
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2019 1 PoC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

CVE-2019-12844
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2019 1 PoC

A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

CVE-2019-2650
WebLogic Server Web Database
N/A
UNKNOWN
EPSS
11.9%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-19493
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

CVE-2019-18418
Software Genérico Web
N/A
UNKNOWN
EPSS
10.6%
2019 1 PoC

clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

CVE-2019-16914
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.

CVE-2019-13585
Software Genérico Web
N/A
UNKNOWN
EPSS
3.8%
2019 3 PoCs

The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.

CVE-2019-11370
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2019 1 PoC

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

CVE-2019-2682
Applications Framework Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this v

CVE-2019-2671
CRM Technical Foundation Web Database
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerabi

CVE-2019-12593
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2019 1 PoC

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

CVE-2019-15780
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVE-2019-17232
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2019-15314
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

CVE-2019-17625
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2019 1 PoC

There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.