1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-5034
Nest Labs General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-125 1 PoC

An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2019-25454
phpMoAdmin Web
5.3
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.

CVE-2019-5097
EmbedThis Web
5.3
MEDIUM
EPSS
7.3%
2019 CWE-835 1 PoC

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.

CVE-2019-1899
Cisco RV130W Wireless-N Multifunction VPN Router Firmware Web Networking
5.3
MEDIUM
EPSS
1.4%
2019 CWE-285 1 PoC

A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.

CVE-2019-3874
kernel General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 3 PoCs

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

CVE-2019-20650
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 before 1.0.1.20.

CVE-2019-20694
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects GS728TP before 6.0.0.48, GS728TPPv2 before 6.0.0.48, GS728TPv2 before 6.0.0.48, GS752TPP before 6.0.0.48, and GS752TPv2 before 6.0.0.48.

CVE-2019-25379
Smoothwall Express Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject malicious scripts. Attackers can submit POST requests with script payloads in the REDIRECT_PAGE or CHILDREN parameters to execute arbitrary JavaScript in user browsers.

CVE-2019-3615
McAfee Database Security (DAM) General
5.3
MEDIUM
EPSS
0.1%
2019 1 PoC

Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.

CVE-2019-20101
Jira Server General
5.3
MEDIUM
EPSS
1.6%
2019 1 PoC

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.

CVE-2019-15165
Software Genérico General
5.3
MEDIUM
EPSS
1.0%
2019 1 PoC

sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.

CVE-2019-3649
Advanced Threat Defense (ATD) General
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.

CVE-2019-3888
undertow Web Windows
5.3
MEDIUM
EPSS
0.6%
2019 CWE-532 1 PoC

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVE-2019-5043
Nest Labs General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 1 PoC

An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability.

CVE-2019-19003
eSOMS Web
5.3
MEDIUM
EPSS
0.4%
2019 CWE-16 1 PoC

For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.

CVE-2019-3650
Advanced Threat Defense (ATD) General
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.

CVE-2019-4471
Cognos Analytics Web
5.3
MEDIUM
EPSS
0.3%
2019 1 PoC

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for a sensitive cookie in an HTTPS session. A remote attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 163780.

CVE-2019-3883
389-ds-base Windows
5.3
MEDIUM
EPSS
0.9%
2019 CWE-772 1 PoC

In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

CVE-2019-25230
Xperience General
5.3
MEDIUM
EPSS
0.1%
2019 CWE-497 1 PoC

An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.

CVE-2019-17655
Fortinet FortiOS and FortiProxy Networking
5.3
MEDIUM
EPSS
0.2%
2019 1 PoC

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.