1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-20437
Software Genérico Web
6.1
MEDIUM
EPSS
0.8%
2019 1 PoC

An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect's URI as the provisioning claim in the advanced claim configuration of the same Identity Provider. The attacker also needs to have privileges to log in to the management console, and to add and update identity provider configurations.

CVE-2019-4632
Security Secret Server Web
6.1
MEDIUM
EPSS
0.2%
2019 1 PoC

IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170004.

CVE-2019-18567
Bromium client General
6.1
MEDIUM
EPSS
0.3%
2019 CWE-362 1 PoC

Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denial of service.

CVE-2019-3648
McAfee Total Protection Windows
6.1
MEDIUM
EPSS
0.2%
2019 2 PoCs

A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.

CVE-2019-20744
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2019 1 PoC

NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

CVE-2019-18991
Software Genérico Networking
6.1
MEDIUM
EPSS
0.0%
2019 1 PoC

A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

CVE-2019-20665
Software Genérico Web
6.0
MEDIUM
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20672
Software Genérico Web
6.0
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20669
Software Genérico Web
6.0
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20668
Software Genérico Web
6.0
MEDIUM
EPSS
0.5%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20661
Software Genérico Web
6.0
MEDIUM
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20675
Software Genérico Web
6.0
MEDIUM
EPSS
0.5%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20666
Software Genérico Web
6.0
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-11859
Software Genérico Web
6.0
MEDIUM
EPSS
0.0%
2019 1 PoC

A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.

CVE-2019-20639
Software Genérico Web
6.0
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20664
Software Genérico Web
6.0
MEDIUM
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-20677
Software Genérico Web
6.0
MEDIUM
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

CVE-2019-12814
Software Genérico General
5.9
MEDIUM
EPSS
18.1%
2019 6 PoCs

A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

CVE-2019-19097
eSOMS General
5.9
MEDIUM
EPSS
0.2%
2019 CWE-16 1 PoC

ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.

CVE-2019-25013
Software Genérico General
5.9
MEDIUM
EPSS
0.8%
2019 1 PoC

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.