1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-1897
Cisco RV130W Wireless-N Multifunction VPN Router Firmware Web Networking
5.3
MEDIUM
EPSS
4.6%
2019 CWE-285 1 PoC

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for device disconnection and providing the connected device information. A successful exploit could allow the attacker to deny service to specific clients that are connected to the guest network.

CVE-2019-25422
Comodo Dome Firewall Web Networking
5.3
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for stored XSS to execute arbitrary JavaScript in administrator browsers.

CVE-2019-5065
Blynck Inc General
5.3
MEDIUM
EPSS
0.3%
2019 CWE-125 1 PoC

An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially crafted packet can cause an unterminated strncpy, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.

CVE-2019-11478
Linux kernel Networking
5.3
MEDIUM
EPSS
29.8%
2019 CWE-770 7 PoCs

Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.

CVE-2019-3654
Client Proxy (MCP) Windows
5.3
MEDIUM
EPSS
0.1%
2019 1 PoC

Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network administrator.

CVE-2019-10184
undertow Web
5.3
MEDIUM
EPSS
1.5%
2019 CWE-862 1 PoC

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVE-2019-20462
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2019 1 PoC

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access point that the device used.

CVE-2019-3598
McAfee Agent (MA) General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets.

CVE-2019-1898
Cisco RV130W Wireless-N Multifunction VPN Router Firmware Web Networking ⚡ nuclei
5.3
MEDIUM
EPSS
78.7%
2019 CWE-285 1 PoC

A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file.

CVE-2019-14855
gnupg2 General
5.3
MEDIUM
EPSS
0.3%
2019 CWE-326 1 PoC

A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

CVE-2019-11479
Linux kernel Networking
5.3
MEDIUM
EPSS
13.4%
2019 CWE-405 4 PoCs

Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.

CVE-2019-25337
OwnCloud Web Cloud
5.3
MEDIUM
EPSS
0.2%
2019 CWE-203 1 PoC

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.

CVE-2019-25419
Comodo Dome Firewall Web Networking
5.3
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.

CVE-2019-20650
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2019 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 before 1.0.1.20.

CVE-2019-25682
CMSsite Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-352 1 PoC

CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.

CVE-2019-3615
McAfee Database Security (DAM) General
5.3
MEDIUM
EPSS
0.1%
2019 1 PoC

Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.

CVE-2019-3874
kernel General
5.3
MEDIUM
EPSS
0.2%
2019 CWE-400 3 PoCs

The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

CVE-2019-1899
Cisco RV130W Wireless-N Multifunction VPN Router Firmware Web Networking
5.3
MEDIUM
EPSS
1.4%
2019 CWE-285 1 PoC

A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.

CVE-2019-5097
EmbedThis Web
5.3
MEDIUM
EPSS
7.3%
2019 CWE-835 1 PoC

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.

CVE-2019-25454
phpMoAdmin Web
5.3
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.