2131 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-20841
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks.

CVE-2019-16125
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.6%
2019 1 PoC

In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.

CVE-2019-2888
WebLogic Server DevOps Web Database
N/A
UNKNOWN
EPSS
75.1%
2019 2 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2019-19210
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2019 2 PoCs

Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

CVE-2019-15780
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.1%
2019 1 PoC

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVE-2019-17232
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2019 1 PoC

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

CVE-2019-17228
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
4.1%
2019 1 PoC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

CVE-2019-5973
Online Lesson Booking Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2019-18418
Software Genérico Web
N/A
UNKNOWN
EPSS
10.6%
2019 1 PoC

clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

CVE-2019-15314
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

CVE-2019-17625
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2019 1 PoC

There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.

CVE-2019-9585
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata.

CVE-2019-2751
HTTP Server Web Database
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2019-2953
Hospitality Cruise Dining Room Management Web Database
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Vulnerability in the Oracle Hospitality Cruise Dining Room Management product of Oracle Hospitality Applications (component: Web Service). The supported version that is affected is 8.0.80. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Dining Room Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Cruise Dining Room Management accessible data as well as unauthorized update, insert or delete access to some of Orac

CVE-2019-9086
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.

CVE-2019-19912
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

CVE-2019-2487
Transportation Management Web Database
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: UI Infrastructure). Supported versions that are affected are 6.3.7, 6.4.1, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Management accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.

CVE-2019-13476
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.

CVE-2019-15649
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.8%
2019 1 PoC

The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

CVE-2019-15816
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.