555 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-3888
undertow Web Windows
5.3
MEDIUM
EPSS
0.6%
2019 CWE-532 1 PoC

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVE-2019-25315
WP Server Log Viewer Web Windows
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.

CVE-2019-25297
Poll, Survey & Quiz Maker Plugin by Opinion Stage Web Windows
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 3 PoCs

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

CVE-2019-25314
Duplicate-Post Web Windows
4.8
MEDIUM
EPSS
0.0%
2019 1 PoC

Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

CVE-2019-3640
Data Loss Prevention Windows
4.8
MEDIUM
EPSS
0.1%
2019 1 PoC

Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.

CVE-2019-3641
Threat Intelligence Exchange Server (TIE Server) Web Windows
4.5
MEDIUM
EPSS
0.2%
2019 CWE-285 1 PoC

Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.

CVE-2019-3634
Data Loss Prevention (DLPe) for Windows Windows
4.4
MEDIUM
EPSS
0.0%
2019 1 PoC

Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory.

CVE-2019-3633
Data Loss Prevention (DLPe) for Windows Windows
4.4
MEDIUM
EPSS
0.0%
2019 1 PoC

Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory.

CVE-2019-19980
Software Genérico Web Windows
4.3
MEDIUM
EPSS
0.2%
2019 1 PoC

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.

CVE-2019-19983
Software Genérico Web Windows
4.3
MEDIUM
EPSS
0.3%
2019 1 PoC

In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.

CVE-2019-3880
samba Web Windows
4.2
MEDIUM
EPSS
3.4%
2019 CWE-22 1 PoC

A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.

CVE-2019-3591
Data Loss Prevention ePO extension Web Windows
3.9
LOW
EPSS
0.2%
2019 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote website which is correctly blocked by DLPe Web Protection. This would then render as an XSS when the DLP Admin viewed the event in the ePO UI.

CVE-2019-11046
PHP Web Windows
3.7
LOW
EPSS
8.2%
2019 CWE-125 1 PoC

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.

CVE-2019-11044
PHP Web Windows
3.7
LOW
EPSS
8.0%
2019 CWE-170 1 PoC

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

CVE-2019-1573
GlobalProtect Agent Networking Windows
2.5
LOW
EPSS
0.2%
2019 CWE-226 1 PoC

GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.

CVE-2019-15825
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.0%
2019 1 PoC

The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.

CVE-2019-5005
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

CVE-2019-17239
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.

CVE-2019-9801
Thunderbird Windows
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVE-2019-15833
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.