1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-20462
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2019 1 PoC

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial interface and rebooting the device, a large amount of information is disclosed. This includes the view password and the password of the Wi-Fi access point that the device used.

CVE-2019-3598
McAfee Agent (MA) General
5.3
MEDIUM
EPSS
0.4%
2019 1 PoC

Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets.

CVE-2019-25708
Heatmiser Wifi Thermostat Web
5.3
MEDIUM
EPSS
0.0%
2019 CWE-352 1 PoC

Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting the networkSetup.htm endpoint with parameters usnm, usps, and cfps to modify the admin username and password without user consent.

CVE-2019-20743
Software Genérico Web
5.2
MEDIUM
EPSS
0.2%
2019 1 PoC

NETGEAR WAC510 devices before 8.0.1.3 are affected by stored XSS.

CVE-2019-25387
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the xtaccess.cgi endpoint. Attackers can inject script payloads through the EXT, DEST_PORT, or COMMENT parameters via POST requests to execute arbitrary JavaScript in victim browsers.

CVE-2019-25252
VidiU Pro Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-352 2 PoCs

Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page.

CVE-2019-25297
Poll, Survey & Quiz Maker Plugin by Opinion Stage Web Windows
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 3 PoCs

Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes when a victim views an affected page.

CVE-2019-25417
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the protocol parameter. Attackers can send POST requests to the QoS rules management endpoint with JavaScript payloads in the protocol parameter to execute arbitrary code in administrator browsers.

CVE-2019-25429
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the openvpn_advanced endpoint. Attackers can inject JavaScript code through the GLOBAL_NETWORKS and GLOBAL_DNS parameters via POST requests to execute arbitrary scripts in users' browsers.

CVE-2019-25388
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the ipblock.cgi endpoint. Attackers can inject script tags through the SRC_IP and COMMENT parameters in POST requests to execute arbitrary JavaScript in users' browsers.

CVE-2019-25228
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-497 1 PoC

An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.

CVE-2019-25448
OrientDB Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the name parameter. Attackers can send POST requests to the document endpoint with JavaScript code in the name field to execute arbitrary scripts when users view the application.

CVE-2019-25384
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the portfw.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the EXT, SRC_PORT_SEL, SRC_PORT, DEST_IP, DEST_PORT_SEL, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.

CVE-2019-25375
OPNsense Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the mailserver parameter. Attackers can send POST requests to the monit interface with JavaScript payloads in the mailserver parameter to execute arbitrary code in users' browsers.

CVE-2019-25412
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST parameter. Attackers can send POST requests to the /korugan/time endpoint with script payloads in the NTP_SERVER_LIST parameter to execute arbitrary JavaScript in users' browsers.

CVE-2019-25389
Smoothwall Express Web
5.1
MEDIUM
EPSS
0.1%
2019 CWE-79 1 PoC

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers can craft requests to the timedaccess.cgi endpoint with script payloads in the MACHINES parameter to execute arbitrary JavaScript in users' browsers.

CVE-2019-25356
MP-4200 Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a cross-site scripting vulnerability in the admin configuration page. Attackers can inject malicious scripts via crafted POST requests with malformed 'admin' and 'person' parameters, allowing execution of arbitrary JavaScript in the context of an authenticated user's browser session.

CVE-2019-4444
API Connect Web
5.1
MEDIUM
EPSS
0.1%
2019 1 PoC

IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.

CVE-2019-25427
Comodo Dome Firewall Web Networking
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the antispyware endpoint. Attackers can send POST requests with JavaScript payloads in the DNSMASQ_WHITELIST or DNSMASQ_BLACKLIST parameters to execute arbitrary code in users' browsers.

CVE-2019-25449
OrientDB Web
5.1
MEDIUM
EPSS
0.0%
2019 CWE-79 1 PoC

OrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON payloads to the document endpoint. Attackers can send POST requests to /document/demodb/-1:-1 with script tags in the name parameter to execute arbitrary JavaScript in users' browsers.