11 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-13478
Software Genérico Web Windows
9.9
CRITICAL
EPSS
2.1%
2019 1 PoC

The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.

CVE-2019-11204
TIBCO Spotfire Statistics Services Windows
9.9
CRITICAL
EPSS
0.5%
2019 1 PoC

The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database, JMX, LDAP, Windows service account, and user credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions up to and including 7.11.1; 10.0.0.

CVE-2019-25213
Advanced Access Manager – Access Governance for WordPress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
40.2%
2019 CWE-22 0 PoCs

The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attackers to read any file on the server, including sensitive files such as wp-config.php

CVE-2019-1205
Microsoft SharePoint Server 2019 Windows
9.8
CRITICAL
EPSS
9.5%
2019 2 PoCs

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same permissions as the current user. To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Word software. Two possible email attack scenarios exist for this vulnerability: With the first e

CVE-2019-0604
🔥 KEV Microsoft SharePoint Server Windows
9.8
CRITICAL
EPSS
94.4%
2019 7 PoCs

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

CVE-2019-0708
🔥 KEV Windows Windows
9.8
CRITICAL
EPSS
94.5%
2019 119 PoCs

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVE-2019-25141
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2019 CWE-862 1 PoC

The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings and arbitrary options on the site that can be used to inject new administrative user accounts.

CVE-2019-4087
Spectrum Protect Windows
9.8
CRITICAL
EPSS
14.1%
2019 1 PoC

IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by servers and storage agents in response to specifically crafted communication exchanges. By sending an overly long request, a remote attacker could overflow a buffer and execute arbitrary code on the system with instance id privileges or cause the server or storage agent to crash. IBM X-Force ID: 157510.

CVE-2019-25138
User Submitted Posts – Enable Users to Submit Posts from the Front End Web Windows
9.8
CRITICAL
EPSS
5.5%
2019 CWE-434 1 PoC

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVE-2019-19915
Software Genérico Web Windows
9.0
CRITICAL
EPSS
0.2%
2019 1 PoC

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.