555 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-0623
Windows Windows
N/A
UNKNOWN
EPSS
34.2%
2019 2 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CVE-2019-15895
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

CVE-2019-14205
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.2%
2019 2 PoCs

A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

CVE-2019-0555
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVE-2019-15598
treekill Windows
N/A
UNKNOWN
EPSS
3.8%
2019 CWE-94 1 PoC

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

CVE-2019-1000031
article2pdf Wordpress plug-in Web Windows
N/A
UNKNOWN
EPSS
1.4%
2019 2 PoCs

A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25, 0.26, 0.27. Visiting PDF generation link but not following the redirect will leave behind a PDF file on disk which will never be deleted by the plug-in.

CVE-2019-15646
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

CVE-2019-15774
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.4%
2019 2 PoCs

The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVE-2019-20204
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2019 3 PoCs

The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.

CVE-2019-13575
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
2.0%
2019 1 PoC

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

CVE-2019-9908
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 3 PoCs

The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.

CVE-2019-3974
Tenable Nessus Windows
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition.

CVE-2019-19731
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.4%
2019 1 PoC

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

CVE-2019-15687
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.

CVE-2019-14789
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVE-2019-20173
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
10.0%
2019 1 PoC

The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

CVE-2019-13115
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
42.4%
2019 1 PoC

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.

CVE-2019-19134
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2019 1 PoC

The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.

CVE-2019-14787
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

CVE-2019-9880
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.9%
2019 3 PoCs

An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.