1326 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-3663
Advanced Threat Defense (ATD) General
9.8
CRITICAL
EPSS
0.4%
2019 2 PoCs

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further details

CVE-2019-20695
Software Genérico General
9.4
CRITICAL
EPSS
0.3%
2019 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects SRK60 before 2.3.5.106, SRR60 before 2.3.5.106, and SRS60 before 2.3.5.106.

CVE-2019-17137
AC1200 Networking
9.4
CRITICAL
EPSS
0.4%
2019 CWE-626 1 PoC

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of path strings. By inserting a null byte into the path, the user can skip most authentication checks. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-8616.

CVE-2019-25441
thesystem General
9.3
CRITICAL
EPSS
6.2%
2019 CWE-78 1 PoC

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.

CVE-2019-25614
Free Float FTP General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-787 1 PoC

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

CVE-2019-25487
RB-1732 Web Networking
9.3
CRITICAL
EPSS
0.2%
2019 CWE-639 1 PoC

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.

CVE-2019-25709
CF Image Hosting Script General
9.3
CRITICAL
EPSS
0.4%
2019 CWE-552 1 PoC

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.

CVE-2019-25646
Mail Carrier General
9.3
CRITICAL
EPSS
0.7%
2019 CWE-787 1 PoC

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.

CVE-2019-25714
A8-V5 Collaborative Management Software General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-434 1 PoC

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).

CVE-2019-17535
Software Genérico Web
9.3
CRITICAL
EPSS
0.3%
2019 1 PoC

Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.

CVE-2019-25471
FileThingie Web
9.3
CRITICAL
EPSS
0.8%
2019 CWE-22 1 PoC

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary commands through the extracted PHP files.

CVE-2019-25568
Memu Play General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-306 1 PoC

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

CVE-2019-25291
Smartliving SmartLAN/G/SI General
9.3
CRITICAL
EPSS
0.1%
2019 CWE-798 2 PoCs

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.

CVE-2019-25322
Heatmiser Netmonitor General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-798 1 PoC

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

CVE-2019-25364
Win10 MailCarrier General
9.3
CRITICAL
EPSS
0.4%
2019 CWE-121 1 PoC

MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.

CVE-2019-25687
Pegasus CMS Web
9.3
CRITICAL
EPSS
1.1%
2019 CWE-22 1 PoC

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.

CVE-2019-25628
Download Accelerator Plus DAP General
9.3
CRITICAL
EPSS
0.2%
2019 CWE-787 1 PoC

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.

CVE-2019-25468
NetGain EM Plus General
9.3
CRITICAL
EPSS
0.3%
2019 CWE-94 1 PoC

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code and retrieve command output.

CVE-2019-25362
WMV to AVI MPEG DVD WMV Convertor General
9.3
CRITICAL
EPSS
0.1%
2019 CWE-787 2 PoCs

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.

CVE-2019-8990
TIBCO ActiveMatrix BusinessWorks Web
9.1
CRITICAL
EPSS
2.1%
2019 1 PoC

The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic Authentication" policy is used in conjunction with an XML Authentication resource. The BusinessWorks engine might instead use credentials from a prior HTTP request for authorization purposes. Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to a