1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-11049
PHP Web Windows
6.5
MEDIUM
EPSS
2.8%
2019 CWE-415 1 PoC

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

CVE-2019-5786
🔥 KEV Chrome General
6.5
MEDIUM
EPSS
89.4%
2019 1 PoC

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVE-2019-6693
🔥 KEV FortiGate General
6.5
MEDIUM
EPSS
72.2%
2019 3 PoCs

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CVE-2019-5014
Winco Firefly General
6.5
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.

CVE-2019-3474
Filr General
6.5
MEDIUM
EPSS
3.3%
2019 CWE-22 1 PoC

A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

CVE-2019-9102
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2019 1 PoC

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.

CVE-2019-3738
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.0%
2019 CWE-325 7 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

CVE-2019-19093
eSOMS General
6.5
MEDIUM
EPSS
0.2%
2019 CWE-521 1 PoC

eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

CVE-2019-19000
eSOMS Web
6.5
MEDIUM
EPSS
0.2%
2019 CWE-16 1 PoC

For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

CVE-2019-8988
TIBCO Data Science for AWS Web Cloud
6.5
MEDIUM
EPSS
0.2%
2019 1 PoC

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and deletions that should be denied. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVE-2019-7307
apport General
6.5
MEDIUM
EPSS
0.0%
2019 CWE-367 2 PoCs

Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubuntu5 contained a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml file, which allows a local attacker to replace this file with a symlink to any other file on the system and so cause Apport to include the contents of this other file in the resulting crash report. The crash report could then be read by that user either by causing it to be uploaded and reported to Launchpad, or by leveraging some other vulnerability to read the resulting crash report, and so al

CVE-2019-9493
MyCar Controls General
6.5
MEDIUM
EPSS
9.2%
2019 CWE-798 1 PoC

The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data from a target MyCar unit. This may allow the attacker to learn the location of a target, or gain unauthorized physical access to a vehicle. This issue affects AutoMobility MyCar versions prior to 3.4.24 on iOS and versions prior to 4.1.2 on Android. This issue has additionally been fixed in Carlink, Link, Visions MyCar, and MyCar Kia.

CVE-2019-5825
🔥 KEV Chrome Web
6.5
MEDIUM
EPSS
73.7%
2019 2 PoCs

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2019-3740
RSA BSAFE Crypto-J General
6.5
MEDIUM
EPSS
1.2%
2019 CWE-310 6 PoCs

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

CVE-2019-14824
389-ds-base General
6.5
MEDIUM
EPSS
0.4%
2019 CWE-732 1 PoC

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVE-2019-15903
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2019 7 PoCs

In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

CVE-2019-15258
Cisco SPA112 2-Port Phone Adapter Networking
6.5
MEDIUM
EPSS
0.4%
2019 CWE-399 1 PoC

A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of user-supplied requests to the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the device to stop responding, requiring manual intervention for recovery.

CVE-2019-5070
Epignosis Database
6.5
MEDIUM
EPSS
0.3%
2019 CWE-89 1 PoC

An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

CVE-2019-25139
Coming Soon Page & Maintenance Mode Web Windows
6.5
MEDIUM
EPSS
0.1%
2019 CWE-862 1 PoC

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset.

CVE-2019-9900
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2019 1 PoC

When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.